You are on page 1of 5

CCNP Security - SENSS

Two Zone Firewall Configuration


IOS ZBPF Configuration Steps
» Define security zones
» Configure layer 4 inspect type class-map
•  Match on traffic
» Configure layer 4 inspect type policy-map
•  Bind the class-maps
•  For each class-map define firewall action
» Configure zone-pair
•  Bind the policy-map
» Attach interfaces to security zones
Copyright © www.ine.com
IOS ZBPF Verification
» Verify security-zones
•  show policy-firewall config zone
•  show zone security
» Verify class-maps
•  show policy-firewall config class-map
•  show class-map type inspect
» Verify policy-maps
•  show policy-firewall config policy-map
•  show policy-map type inspect
Copyright © www.ine.com
IOS ZBPF Verification
» Verify zone-pair
•  show policy-firewall config zone-pairs
•  show zone-pair security
» Verify active sessions in the state table
•  show policy-firewall session zone-pair <NAME>
•  show policy-map type inspect zone-pair sessions

Copyright © www.ine.com
Q&A

Copyright © www.ine.com All rights reserved.

You might also like