Question about statefull inspection on IOS firewall

Unanswered Question
Jan 6th, 2010

Hi !

I need for test purposes to initiate tcp traffic from my router to the internet

i have set an inspect list on the outbound interface:

router(config)# int eth0

routert(config-if)# ip inspect myfw out

but the tcp sessions initiated from the router are not added int the inspection table and the tcp packets are dropped on their way back

Is there a solution to do this ?



I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Kent Heide Wed, 01/06/2010 - 08:39

If what you're meaning is traffic initiating from the router itself like for example if you want to telnet from the router you need to add a statement in your `ip inspect` config.

What you need is the `router-traffic` keyword after your inspect configuration.

ip inspect myfw tcp router-traffic


This Discussion