Zbfw
May 18, 2021 ・0 comments
Zbfw. Now it's time to implement zone-based firewalls (ZBFW). Realistically ZBFW is no substitute to a dedicated firewall as it does not have the NGFW features supported by most vendors.
Today's challenge was to get to grips with Cisco's ZBFW, there are a few examples out there if you google but this cisco pdf was the best resource I found.
Router interfaces are assigned to specific security zones, and then interzone traffic is explicitly permitted or denied based on the security policy.
We create policys between zones and assign interfaces to zones instead of applying CBAC rules to interfaces. We will demonstrate capability of Cisco router in participating Cisco TrustSec including joining SGT trust domain, Network Device Authorization, SGT propagation, and enforcement. So far the VPN topology has come along pretty well, there have been a few things that need to be put into OneNote but it's all good learning.






Post a Comment
If you can't commemt, try using Chrome instead.