Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Zone Based Firewall and HSRP

All,

I have a retail customer that has 2 routers at each store location running HSRP.  Each router has a T1 to the internet and a DMVPN tunnel back to corporate and both routers are running ZBF. Under normal circumstances this works well.  But in a failover situation, when the T1 on Router 1 fails HSRP makes the 0.0.0.0 route be Router 2.  Traffic originating from the LAN uses Router 1 as the default gateway, so they are still sourcing from Router 1.  Return traffic in a failover scenario comes through Router 2 to get back to the LAN side.  This would be fine except ZBF on Router 2 never sees the request so it blocks the return traffic.  The only way I have been able to get this to work is to pass the traffic instead of inspecting it within ZBF.  But this defeats the purpose of traffic inspection.  I am at a loss as to how to get this solution to work.

Everyone's tags (3)
1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: Zone Based Firewall and HSRP

Hi,

What you need here is stateful failover for the firewall feature. Unfortunately that's only supported in the classic IOS firewall and not for the Zone Based firewall, see http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ht_sfo.html.

Thanks,

Wen

7 REPLIES
Cisco Employee

Re: Zone Based Firewall and HSRP

Hi,

What you need here is stateful failover for the firewall feature. Unfortunately that's only supported in the classic IOS firewall and not for the Zone Based firewall, see http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ht_sfo.html.

Thanks,

Wen

Cisco Employee

Re: Zone Based Firewall and HSRP

Hi Wen,

Thank you for sharing this information! As a Cisco employee, do you perhaps have any internal information whether a stateful failover feature for CBAC/Zone Based Firewall is being considered?

Best regards,

Peter

Cisco Employee

Re: Zone Based Firewall and HSRP

Hi, Peter:

Zone Based Firewall stateful HA support is being considered, and last I checked is on the roadmap to be implemented in 15M/T release sometime in mid-2011. That said, please don't quote me on this as the standard "I don't represent the official Cisco view" disclaimer applies . I would suggest you contact your cisco rep to confirm this and help make the business case for it.

Thanks,

Wen

Cisco Employee

Re: Zone Based Firewall and HSRP

Hi Wen,

Thank you very much for the info.

That said, please don't quote me on this as the standard "I don't represent the official Cisco view" disclaimer applies .

Surely, I am taking it that way.

Best regards,

Peter

New Member

Zone Based Firewall and HSRP

Does anyone have any news regarding this feature?

It would be great to have stateful failover for ZBFW /w HSRP.

New Member

Re: Zone Based Firewall and HSRP

Thanks for your insight, Wen.  I had considered a similar config.  But I was hoping that we could achieve this somehow with ZBF.  I will test this config and see if I get any better outcome.  Thanks again.

Cisco Employee

Re: Zone Based Firewall and HSRP

Hi,

Unfortunately there's really no other way around this. The firewall (classic or ZBF) is stateful by definition, so it can't work with asymmetric connections. For now we are stuck with doing this with the classic firewall until the HA feature is added for ZBF.

Thanks,

Wen

1428
Views
5
Helpful
7
Replies
CreatePlease login to create content