IOS Zone-based Policy Firewall questions

Unanswered Question

1. Why doesn't "drop log" policy-map action send unreachables? Is this a bug or feature?

2. Why doesn't ZPF control multicasts terminated at the self zone (EIGRP, for example), so it is not possible to control which multicasts are accepted and which aren't. Is this a bug or feature?

3. Why is SMTP guard enabled by default and cannot be disabled if "match protocol smtp" is used? Is this a bug or feature?

4. Does cisco have performance metrics for ZPF compared to traditional CBAC?

IOS 12.4(15)T


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
juan_m_12 Tue, 02/26/2008 - 07:55

i have the same problem with the SMTP being blocked,

have you found a way to make it work??


This Discussion