ZPF Firewall Configuration Guide

You might also like

Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 2

ZPF Firewall Configuration Guide

Create zones

ZPFrouter(config)#zone security PRIVATE


ZPFrouter(config-sec-zone)#exit
ZPFrouter(config)#zone sec
ZPFrouter(config)#zone security PUBLIC
ZPFrouter(config-sec-zone)#exit

Create Class Maps

ZPFrouter(config)#class-map type inspect match-all PRIVATE-OUTBOUND-CMAP


ZPFrouter(config-cmap)#match any
ZPFrouter(config-cmap)#exit

Create Policy Map(s)

ZPFrouter(config)#policy-map type inspect PRIVATE-OUTBOUND-PMAP


ZPFrouter(config-pmap)#class type inspect PRIVATE-OUTBOUND-CMAP
ZPFrouter(config-pmap-c)#inspect
%No specific protocol configured in class PRIVATE-OUTBOUND-CMAP for inspection. All protocols will
be inspected
ZPFrouter(config-pmap-c)#exit
ZPFrouter(config-pmap)#exit
Create Zone Pairs and Associate Policy

ZPFrouter(config)#zone-pair security PRIVATE-OUTBOUND-PAIR source PRIVATE destination PUBLIC


ZPFrouter(config-sec-zone-pair)#service-policy type inspect PRIVATE-OUTBOUND-PMAP

Assign Interfaces to Security Zones

ZPFrouter(config-sec-zone-pair)#int g0/1
ZPFrouter(config-if)#zone-member security PRIVATE
ZPFrouter(config-if)#int g0/0
ZPFrouter(config-if)#zone-member security PUBLIC
ZPFrouter(config-if)#exit

You might also like