Skip to Content

ZBF - inspect does NOT work?

No replies
mk
mk's picture
Offline
Joined: 2011-06-28
Posts: 18

<code>
Zone: Outside
  Member Interfaces:
    Dialer0

 

Zone: Inside
  Member Interfaces:
    Virtual-Template1
    Vlan1102

 

Zone: Guest
  Member Interfaces:
    Vlan1104

Zone-pair              : Inside-to-Guest
Source Zone            : Inside
Destination Zone       : Guest
Service-policy inspect : Zone-Inside-to-Guest
  Class-map : Default-Inspection(match-any)
  Action : inspect

Class Map type inspect match-any Default-Inspection (id 10)
  Description: Default protocol Inspection class
   Match protocol tcp
   Match protocol udp
   Match protocol icmp
</code>

My question is: I cannot make it work the ZBF between my internal zones.
As you can see above, I've got Zone-Pair: Inside-to-Guest with
'inspect'. Unfortunately, when I tried to ping for the first time, i
received:

<code>
%FW-6-DROP_PKT: Dropping icmp session GUEST:0    INSIDE:0  due to  policy match failure with ip ident 0
</code>

It indicated that the traffic going BACK was blocked... WHY? There is 'inspect'
 
So
I created a new pair: Guest-to-Inside and I changed everything to pass.
It DID work. But that is not what I wanted! I wanted INSIDE to access
GUEST but Guest should not access Inside. I assumed I could do it with
'inspect' but it did now work.
 
Let me add that I have an exactly the same zone-pair and classes/policies for Inside-to-Outside and it does work with inspect.
 
Why can I not 'inspect'  between my internal zones? Is it because there is no NAT?

Your rating: None Average: 4 (1 vote)

You must be signed in to contribute to the forums.

Not registered? Click here to create an account. It only takes a minute and it's free!

Already signed up? Click here to login.



Dr. Radut | forum