cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
718
Views
0
Helpful
1
Replies

IOS FW Order of operation for NAT & Inspection

markbowman
Level 1
Level 1

Can someone answer the questions on the text file? It is just an order of operation question on the IOS FW.

1 Reply 1

Alex Yeung
Cisco Employee
Cisco Employee

From ingress to egress:

stateless IOS IPS -> IPSec decryption -> auth proxy -> input ACL -> virtual fragment inspection -> NAT before routing -> routeing -> NAT after routing -> stateful IOS IPS -> outbound ACL -> ISO FW -> IPSec encryption

HTH.

Alex Yeung

Review Cisco Networking products for a $25 gift card