<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco IOS Zone Based Policy Firewall</title>
	<atom:link href="http://nat0.net/cisco-ios-zone-based-policy-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://nat0.net/cisco-ios-zone-based-policy-firewall/</link>
	<description>a blog about networking, Cisco-solutions and security</description>
	<lastBuildDate>Fri, 03 Feb 2012 14:38:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Jimmy Larsson</title>
		<link>http://nat0.net/cisco-ios-zone-based-policy-firewall/#comment-41</link>
		<dc:creator>Jimmy Larsson</dc:creator>
		<pubDate>Sat, 06 Feb 2010 08:46:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogg.kvistofta.nu/?p=680#comment-41</guid>
		<description>Hi Dazzler!

Thanks for notifying me about the typo, it´s corrected now!

Next step is to also do deep packet inspection in the same config. Like &quot;also, inside users should be able to http to internet, except to sites with the string &quot;piratebay&quot; in the url. Or something. ;)</description>
		<content:encoded><![CDATA[<p>Hi Dazzler!</p>
<p>Thanks for notifying me about the typo, it´s corrected now!</p>
<p>Next step is to also do deep packet inspection in the same config. Like &#8220;also, inside users should be able to http to internet, except to sites with the string &#8220;piratebay&#8221; in the url. Or something. <img src='http://nat0.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jimmy Larsson</title>
		<link>http://nat0.net/cisco-ios-zone-based-policy-firewall/#comment-40</link>
		<dc:creator>Jimmy Larsson</dc:creator>
		<pubDate>Fri, 05 Feb 2010 17:29:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogg.kvistofta.nu/?p=680#comment-40</guid>
		<description>Thanks for the input. I have corrected it now.

I was thinking about doing a third thing; a level7-inspection of something. Like &quot;Also, inside host should be able to http to urls except all .com-addresses&quot;. Hmm. Sounds like an idea for  next blog post.</description>
		<content:encoded><![CDATA[<p>Thanks for the input. I have corrected it now.</p>
<p>I was thinking about doing a third thing; a level7-inspection of something. Like &#8220;Also, inside host should be able to http to urls except all .com-addresses&#8221;. Hmm. Sounds like an idea for  next blog post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dazzler</title>
		<link>http://nat0.net/cisco-ios-zone-based-policy-firewall/#comment-39</link>
		<dc:creator>Dazzler</dc:creator>
		<pubDate>Fri, 05 Feb 2010 12:24:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogg.kvistofta.nu/?p=680#comment-39</guid>
		<description>Cool example. I too had a hard job with this, especially trying to get it to work staeless as well as stateful..... 

One small typo, below the IP address should read 10.13.13.13.

Task 2. Also allow specific pings outbound
The next task for me is to enable ping from inside hosts to the outside. To make it a bit trickier I decide to make an exception for the internal host 10.11.11.11 who should not be able to ping.

Great work! :-)
</description>
		<content:encoded><![CDATA[<p>Cool example. I too had a hard job with this, especially trying to get it to work staeless as well as stateful&#8230;.. </p>
<p>One small typo, below the IP address should read 10.13.13.13.</p>
<p>Task 2. Also allow specific pings outbound<br />
The next task for me is to enable ping from inside hosts to the outside. To make it a bit trickier I decide to make an exception for the internal host 10.11.11.11 who should not be able to ping.</p>
<p>Great work! <img src='http://nat0.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

