ZBF - inspect does NOT work?
<code>
Zone: Outside
Member Interfaces:
Dialer0
Zone: Inside
Member Interfaces:
Virtual-Template1
Vlan1102
Zone: Guest
Member Interfaces:
Vlan1104
Zone-pair : Inside-to-Guest
Source Zone : Inside
Destination Zone : Guest
Service-policy inspect : Zone-Inside-to-Guest
Class-map : Default-Inspection(match-any)
Action : inspect
Class Map type inspect match-any Default-Inspection (id 10)
Description: Default protocol Inspection class
Match protocol tcp
Match protocol udp
Match protocol icmp
</code>
My question is: I cannot make it work the ZBF between my internal zones.
As you can see above, I've got Zone-Pair: Inside-to-Guest with
'inspect'. Unfortunately, when I tried to ping for the first time, i
received:
<code>
%FW-6-DROP_PKT: Dropping icmp session GUEST:0 INSIDE:0 due to policy match failure with ip ident 0
</code>
It indicated that the traffic going BACK was blocked... WHY? There is 'inspect'
So
I created a new pair: Guest-to-Inside and I changed everything to pass.
It DID work. But that is not what I wanted! I wanted INSIDE to access
GUEST but Guest should not access Inside. I assumed I could do it with
'inspect' but it did now work.
Let me add that I have an exactly the same zone-pair and classes/policies for Inside-to-Outside and it does work with inspect.
Why can I not 'inspect' between my internal zones? Is it because there is no NAT?
Recent comments
23 hours 37 min ago
1 day 7 hours ago
2 days 17 hours ago
5 days 6 hours ago
5 days 8 hours ago
5 days 17 hours ago
5 days 17 hours ago
5 days 17 hours ago
6 days 2 hours ago
1 week 4 days ago