cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
264
Views
0
Helpful
1
Replies

1841 IOS firewall policy off/on

richmorrow624
Level 1
Level 1

I have a 1841 router that is going to be an Internet facing router for a DR site.

Normal operation is to have the main site VPN tunnel to the remote site.

An IOS firewall policy blocking all access but throught the VPN tunnel

If the main site were to have a disaster, we would need to have customers have access to DR servers via the Internet to a block NATed address.

The thing is , I do not want to allow access to these addresses all the time, but I want to be able to quickly remote in and add access to 20 differnet servers on five or six different ports.

Is there a way to save an IOS firewall policy file and dump it to the router where all access is blocked via Internet, then access allowed?

1 Reply 1

pradeepde
Level 5
Level 5

hope Context-Based Access Control will help to you.

CBAC creates temporary openings in access lists at firewall interfaces. These openings are created when specified traffic exits your internal network through the firewall.

Refer this link:

http://www.cisco.com/en/US/products/sw/iosswrel/ps1830/products_feature_guide_chapter09186a00800881be.html#11774

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card