cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
229
Views
0
Helpful
1
Replies

Zone FW working but not matching protocol Class Map

HEATH FREEL
Level 1
Level 1

My configuration is simple and testing has gone well.... I started off with a Class map that only matched on an access list. After successful testing I added a subordinate class map for protocol matching. If appears to be working but the statistics do not show what I expect.

In the attachment you will see the configuration and the output of the "show policy-map type inspect zone-pair inout session" command.

Although it is working I expected to see hits against the protocols I am inspecting. In this case a ping to an outside server should have hits against the ICMP protocol. Same thing it I do an HTTP session - it works but no hits. In reading through the documentation I have configured it correctly, but am I missing something.

BTW - 881 Version 12.4.20T1

Thanks,

Heath

1 Reply 1

mchin345
Level 6
Level 6

Monitor firewall inspection statistics with the show policy-map type inspect zone-pair commands. This commands helps you to identify the problem.

Here is the link to configure.

http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml#cg1

Review Cisco Networking products for a $25 gift card