Professional Documents
Culture Documents
Implementing Firewall
Technologies
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
• Not dependent on ACLs
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Common designs include:
• LAN-to-Internet
• Redundant firewalls
• Complex firewalls
Design steps:
1. Determine the zones
2. Establish policies between zones
3. Design the physical infrastructure
4. Identify subsets within zones and merge traffic requirements
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
• Inspect - Configures Cisco IOS stateful packet inspections.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Command Syntax for
class-map
Sub-Configuration
Command Syntax for
class-map
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Example class-map Configuration
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Command Syntax for
policy-map
Example policy-map
Configuration
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Command Syntax for
zone-pair and
service-policy
Example service-policy
Configuration
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Verification commands:
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Chapter Objectives:
• Implement ACLs to filter traffic and mitigate network attacks on a network.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Thank you.
• Remember, there are
helpful tutorials and user
guides available via your
NetSpace home page. 1
(https://www.netacad.com) 2
• These resources cover a
variety of topics including
navigation, assessments,
and assignments.
• A screenshot has been
provided here highlighting
the tutorials related to
activating exams, managing
assessments, and creating
quizzes.
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 20