cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
2841
Views
0
Helpful
3
Replies

is Router will do statefull Packet inspection like cisco ASA

nagaprasad123
Level 1
Level 1

Hi Team

Can cisco routers will support statefull inspection if so how ?

I was attended an interview, in the managar round he asked me what is the main  difference between Firewall and router/l3 switch ?

in place of firewall we can use router also then why again we need a firewall ?

i just started some basic functionalities of how firewall and router will work. even though the managar not  agree what exactly difference between them.

can any one please guide me what exactly the difference.

looking forward your immediate response.

Thanks

NagaPrasad

3 Replies 3

Julio Carvajal
VIP Alumni
VIP Alumni

Well by default the L3 router/Switch will not have such a stateful table as the ASA firewall for example so if you have ACLs on a pair of interfaces traffic flowing through the box that matches an existing session will go trough without any user configuration intervention.

On a regular L3 device you must explicitly allow the traffic

Note that Cisco Routers support CBAC and ZBFW which basically turn on a Firewall Feature.

Cisco Switches such as the 6500 family support the FWSM and now the ASA-SM which also brings into consideration a Firewall.

Looking for some Networking Assistance? 
Contact me directly at jcarvaja@laguiadelnetworking.com

I will fix your problem ASAP.

Cheers,

Julio Carvajal Segura
http://laguiadelnetworking.com

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hi Julio Carvajal Segura

  Thanks for you response.

But my questions is

1. Can cisco routers will support statefull inspection if so how ?

2. I was attended an interview, in the managar round he asked me what is the main  difference between Firewall and router/l3 switch ?

3. in place of firewall we can use router also then why again we need a firewall ?

Please answer the above

Thanks

NagaPrasad

Hello,

1. Can cisco routers will support statefull inspection if so how ?

I already answered this

Note that Cisco Routers support CBAC and ZBFW which basically turn on a Firewall Feature which means Stateful Inspection.


2. I was attended an interview, in the managar round he asked me what is the main  difference between Firewall and router/l3 switch ?

I already did it as well

Well by default the L3 router/Switch will not have such a stateful table as the ASA firewall for example so if you have ACLs on a pair of interfaces traffic flowing through the box that matches an existing session will go trough without any user configuration intervention.

On a regular L3 device you must explicitly allow the traffic if being filtered somewhere.

3. in place of firewall we can use router also then why again we need a firewall ?

Not all routers support Firewall features and performance or features will not be as good as with a dedicated FW.

Looking for some Networking Assistance? 
Contact me directly at jcarvaja@laguiadelnetworking.com

I will fix your problem ASAP.

Cheers,

Julio Carvajal Segura
http://laguiadelnetworking.com

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card