cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1387
Views
0
Helpful
3
Replies

IOS equivalent to sh conn and sh xlate in PIX

paulkbeyer
Level 1
Level 1

Hey chaps and chapettes.

As the title states, what's the command to track connections through an IOS 12.4 Router with Zone Based Firewalling enabled?

I'm used to getting good output from sh conn and sh xlate on my ASA but I've never tried to do the same thing within IOS.

Help very much appreciated.

Regards

Paul.

1 Accepted Solution

Accepted Solutions

Collin Clark
VIP Alumni
VIP Alumni

Paul-

I have not had a chance to play with zone based firewalling yet, but can't wait. I'm assuming that the translations will be the same as using normal interfaces.

show xlate = show ip nat translations

show conn = show ip nat translations verbose

HTH and please rate.

View solution in original post

3 Replies 3

Collin Clark
VIP Alumni
VIP Alumni

Paul-

I have not had a chance to play with zone based firewalling yet, but can't wait. I'm assuming that the translations will be the same as using normal interfaces.

show xlate = show ip nat translations

show conn = show ip nat translations verbose

HTH and please rate.

Ahhhh! Magic!

Thank you very much, you're a gentleman and a scholar!

Yeah the zone based firewalling makes me feel warm and fuzzy coming from a PIX background into IOS world as it's alot more like that than classic firewalls.. Apart from the supposed performance and administrative benefits it doesn't do much else tho.. apart from WORK I guess! :O)

Thanks again buddy.

Paul.

We also use Netscreen firewalls which use zones,glad to see Cisco catching up. Glad the commands helped.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card