# Zone Based Firewall Configuration Example

**URL:** https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024
**Category:** Lessons Discussion
**Created:** [December 26, 2016, 6:17pm UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024 "2016-12-26T18:17:44Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 26, 2016, 6:17pm UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/1 "2016-12-26T18:17:44Z")

</div>

This topic is to discuss the following lesson:

[https://networklessons.com/cisco/ccie-enterprise-infrastructurezone-based-firewall-configuration-example/](https://networklessons.com/cisco/ccie-enterprise-infrastructurezone-based-firewall-configuration-example/)

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [May 11, 2013, 2:54pm UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/2 "2013-05-11T14:54:44Z")

</div>

Hello René

[Networklessones.com](http://Networklessones.com) is very informative… 🙂

thank you…

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [May 11, 2013, 2:55pm UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/3 "2013-05-11T14:55:51Z")

</div>

Glad you like it 🙂

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [June 12, 2013, 2:34am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/4 "2013-06-12T02:34:21Z")

</div>

Hi Rene,

Really good post to understand the concepts behind the zone based firewall.

Can you advise under what kind of network environments you would use zone based firewall?

Thank you,  
Jay

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [June 13, 2013, 7:04am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/5 "2013-06-13T07:04:21Z")

</div>

Hi Jay,

The Zone Based Firewall is nice to use if you have an ISR with many interfaces that doesn’t run too much traffic and when you don’t have the budget to buy a separate firewall.

Rene

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [November 16, 2013, 11:50am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/6 "2013-11-16T11:50:54Z")

</div>

Thank you Rene . Clean , Simple and very informative.

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [December 5, 2013, 4:06am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/7 "2013-12-05T04:06:44Z")

</div>

Thanks a lot for writing this post. It helped me so much!

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [April 14, 2014, 10:07am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/8 "2014-04-14T10:07:57Z")

</div>

Thanks! very helpful!

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [April 14, 2014, 10:44am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/9 "2014-04-14T10:44:17Z")

</div>

Glad to be of service!

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 20, 2014, 7:06pm UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/10 "2014-07-20T19:06:16Z")

</div>

Hi Rene

What if i would like to inspet protocol which is unavaible i NBAR?  
How can create my own “protocols” to inspect

Thanks  
Luck

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 23, 2014, 11:18am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/11 "2014-07-23T11:18:27Z")

</div>

Hi Rene,

First of all thanks a lot for the very nice posts.

I was trying the same example but the only difference is that i was trying to inspect http traffic (match protocol http). Therefore when i try to generate some web traffic from the VM web browser, the http traffic is blocked. Once i changed the same class-map to the below it works. My question is why when matching http only the web traffic is blocked.

```
ip access-list extended ANY
  permit ip any any 
class-map type inspect LAN-TO-WAN
 match access-group name ANY

```

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 31, 2014, 1:21pm UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/12 "2014-07-31T13:21:41Z")

</div>

Hi Luck,

NBAR is the “lazy” way to match certain protocols. If NBAR doesn’t support your protocol then you have two options:

- Use an Access-list to match on the protocol (TCP/UDP/ICMP/etc) and the port numbers.

OR

- You can create custom protocols for NBAR, you’ll have more options but it’s also a bit more complicated. Take a look here to see what I mean:

> **[QoS: NBAR Configuration Guide, Cisco IOS Release 15M&T - Creating a...](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/qos_nbar/configuration/15-mt/qos-nbar-15-mt-book/nbar-cust-protcl.html#GUID-17EEBC5B-6F3E-446D-9F6D-1A473CFA073D)**
>
> Creating a Custom Protocol

Hope that helps,

Rene

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [August 3, 2014, 9:23pm UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/13 "2014-08-03T21:23:12Z")

</div>

Hello,

Thanks a lot for your explanations regarding the self zone, I’ve been looking for some simple examples and you got it right to the point.

Keep up the good work,

Lionel

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [August 4, 2014, 1:05pm UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/14 "2014-08-04T13:05:24Z")

</div>

You are welcome Lionel.

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [August 6, 2014, 11:03am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/15 "2014-08-06T11:03:29Z")

</div>

Hi Houssam,

If i understand you correctly, with “match protocol http” you were unable to get HTTP traffic inspected so the return traffic was allowed? That should work. What do you see with the show commands or when you enable a debug?

The access-list/class-map example that you have will allow everything from LAN \> WAN, including HTTP.

Rene

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [September 5, 2014, 12:56pm UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/16 "2014-09-05T12:56:00Z")

</div>

Hello Rene,

Excellent article about zone based firewall. Very informative and easy to read and understand the concepts. Thanks.

Regards,  
Maros

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [September 10, 2014, 10:27am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/17 "2014-09-10T10:27:17Z")

</div>

Hi Maros,

Thank you, I’m glad to hear that it was useful!

Rene

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [September 18, 2014, 2:37am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/18 "2014-09-18T02:37:59Z")

</div>

that was useful  
thanks a lot

---

<div class="post-metadata">

### Author: ![venter13](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/v/9f8e36/32.png) [@venter13](https://forum.networklessons.com/u/venter13)
#### Post date: [September 18, 2014, 5:05am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/19 "2014-09-18T05:05:17Z")

</div>

Hi rene,

i want to ask,  
in service policy , they have drop, pass, and inspect..  
i try to use drop and pass, and it still block the traffic..  
so what difference with drop,pass, and inspect..

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [September 22, 2014, 10:40am UTC](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/20 "2014-09-22T10:40:00Z")

</div>

Hi John,

Good question…

When you use drop, the packet is discarded right away.

When you use pass…the packet is allowed outbound but there won’t be a rule for the return traffic so it will be dropped inbound.

Inspect will allow the packet outbound but also automatically creates a rule for the return traffic so that it is allowed inbound.

Does that make sense?

Rene

[Next page](https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024.md?page=2)
