cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
247
Views
0
Helpful
1
Replies

IOS firewall problem

rob.murray
Level 1
Level 1

Hi,

I have an 1841 router on which I wish to run the IOS firewall. This device has a public internet connection via a VRF and I wish to put zone based firewalling in place between this and a public dmz on the same device. My problem is that I cannot seem to allow ESP/AH pass through in the firewall rules. We have other firewalls in the DMZ that terminate VPN tunnels. I have tried to create a class mapp with the match protocol ipsec statement but as soon as I put the inspect in the class map it wont allow IPSEC. Is there a special way to do this?

1 Reply 1

ebreniz
Level 6
Level 6

Here we need to know what version of IOS are you using in the router also need to know whether the command is getting rejected?