What is Zone Based Policy Firewall?
Category:
technology and computing
computer networking
Zone-Based Policy Firewall (also known as Zone-Policy Firewall, or ZFW) changes the firewall configuration from the older interface-based model to a more flexible, more easily understood zone-based model. Interfaces are assigned to zones, and inspection policy is applied to traffic moving between the zones.
Accordingly, what is a zone based firewall?
A Zone-based firewall is an advanced method of stateful firewall. In stateful firewall, a stateful database is maintained in which source IP address, destination IP address, source Port number, destination port number is recorded.
Furthermore, what are the general rules for applying Zone Based Policy Firewall?
Rules for applying Zone-based Policy Firewall:
- A zone must be configured before an interface is assigned to it and an interface can be assigned to only a single zone.
- All traffic to and from an interface within a zone is permitted.
- All traffic between zones is affected by existing policies.
According to the Cisco IOS software advisor, zone-based firewalls were released in 12.4(6)T6 so that would be the minimum IOS release. All of these are later releases but none of them are working.