4.4.1.1 Packet Tracer - Configuring A Zone-Based Policy Firewall (ZPF)
4.4.1.1 Packet Tracer - Configuring A Zone-Based Policy Firewall (ZPF)
Topology
Addressing Table
Objectives
Verify connectivity among devices before firewall configuration.
Configure a zone-based policy (ZPF) firewall on R3.
Verify ZPF firewall functionality using ping, SSH, and a web browser.
Background/Scenario
ZPFs are the latest development in the evolution of Cisco firewall technologies. In this activity, you will
configure a basic ZPF on an edge router R3 that allows internal hosts access to external resources and
blocks external hosts from accessing internal resources. You will then verify firewall functionality from internal
and external hosts.
The routers have been pre-configured with the following:
o Console password: ciscoconpa55
o Password for vty lines: ciscovtypa55
o Enable password: ciscoenpa55
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 1 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 2 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 3 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
b. If the Security Technology package has not been enabled, use the following command to enable the
package.
R3(config)# license boot module c1900 technology-package securityk9
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 4 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
d. Save the running-config and reload the router to enable the security license.
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 5 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
e. Verify that the Security Technology package has been enabled by using the show version command.
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 6 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 7 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
Step 2: Specify a class type of inspect and reference class map IN-NET-CLASS-MAP.
Issue the exit command twice to leave config-pmap-c mode and return to config mode.
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 8 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
Step 2: Specify the policy map for handling the traffic between the two zones.
Attach a policy-map and its associated actions to the zone pair using the service-policy type inspect
command and reference the policy map previously created, IN-2-OUT-PMAP.
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 9 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
Step 3: From PC-C, exit the SSH session on R2 and close the command prompt window.
Step 4: From internal PC-C, open a web browser to the PC-A server web page.
Enter the server IP address 192.168.1.3 in the browser URL field, and click Go. The HTTP session should
succeed. While the HTTP session is active, issue the command show policy-map type inspect zone-pair
sessions on R3 to view established sessions.
Note: If the HTTP session times out before you execute the command on R3, you will have to click the Go
button on PC-C to generate a session between PC-C and PC-A.
What is the source IP address and port number?
192.168.3.3:1031
What is the destination IP address and port number?
10.2.2.2:80
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 10 of 11
Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)
CONCLUSIONES
© 2023 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 11 of 11