<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: ASA vs ZBFW&#x27; in forum &#x27;Cisco&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27720156</link>
<description></description>
<language>en</language>
<pubDate>Tue, 18 Jun 2013 20:40:56 EDT</pubDate>
<lastBuildDate>Tue, 18 Jun 2013 20:40:56 EDT</lastBuildDate>

<item>
<title>Re: ASA vs ZBFW</title>
<link>http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27769814</link>
<description><![CDATA[RyanG1 posted : So just to come full circle on this... i figured out what was going on.<br><br>the router is not tracking the connections properly and anything that was coming back was being denied (but not logged as a deny!)... i figured the only thing i had not done was bump to a higher rev IOS... that did the trick. All consoles now report as open connectivity and ZBFW is processing the traffic just as the ASA does (cpu load is decreased now as well when maxing out my internet download).... i could not find any bugs on this at all from any source.....<br><br>went from c890-universalk9-mz.152-2.T1 to c890-universalk9-mz.152-3.T<br><br>*shrug*<br><br>i should have tried that first but whatever... i hope this helps someone else in the future =)<br><br>ryan<br><small>--<br>Human beings, who are almost unique in having the ability to learn from the experience of others, are also remarkable for their apparent disinclination to do so. -Douglas Adams</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27769814</guid>
<pubDate>Wed, 28 Nov 2012 19:53:23 EDT</pubDate>
</item>

<item>
<title>Re: ASA vs ZBFW</title>
<link>http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27737361</link>
<description><![CDATA[RyanG1 posted : yea i captured traffic coming inbound on the WAN interface and its identical for the most part.<br><br>Im just going to shelve this for now and revisit later.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27737361</guid>
<pubDate>Sat, 17 Nov 2012 15:53:45 EDT</pubDate>
</item>

<item>
<title>Re: ASA vs ZBFW</title>
<link>http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27736398</link>
<description><![CDATA[HELLFIRE posted : <div class="bquote"><said>said by <a href="/profile/582272" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=582272');">RyanG1</a>:</said><p>Honestly if i could find even one shred of info as to how the xbox live service tests, im sure i could find the reasoning to whats going on here but... meh... nothing. <br> </p></div>Wireshark it?  But I feel your pain.  I got a doozy of a one at work... ipad + ios 5 or 6 + two redundant pods of firewalls, POD A is one revision of code behind POD B.  Go thru one pod, it works; go thru the other one it borks.  Last I heard, SOMEone (not me thankfully) has to put in a call to Apple to see why their wonderful new toy is acting so screwy.<br><br>Regards]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27736398</guid>
<pubDate>Sat, 17 Nov 2012 01:40:36 EDT</pubDate>
</item>

<item>
<title>Re: ASA vs ZBFW</title>
<link>http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27733039</link>
<description><![CDATA[RyanG1 posted : Yea i ran a debug on both and logged all traffic and the only difference is that the asa doesnt bind the global public port to the same inside local port and IOS does. I dont think this is the reasoning behind it and i may just put my ASA back in front and have it handle all NAT.<br><br>Honestly if i could find even one shred of info as to how the xbox live service tests, im sure i could find the reasoning to whats going on here but... meh... nothing. <br><br>I just hate situations where it feels like a simple issue but the lack of information about the problem grinds everything to a halt. It also bugs me since i cant figure it out lol.<br><br>Who knows maybe someone will google search this and come up with an answer to this burning question...and should i come across the solution ill post it =)<br><br>I agree though, the asa product is a rather nice piece of hardware and i find it very simple to manage compared to the ordeal of ZBFW haha.<br><br>Ryan<br><small>--<br>Human beings, who are almost unique in having the ability to learn from the experience of others, are also remarkable for their apparent disinclination to do so. -Douglas Adams</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27733039</guid>
<pubDate>Fri, 16 Nov 2012 03:16:36 EDT</pubDate>
</item>

<item>
<title>Re: ASA vs ZBFW</title>
<link>http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27733025</link>
<description><![CDATA[HELLFIRE posted : Couldnt tell you either RyanG1.  Unfortunately I don't have the nuts and bolts into either IOS or ASA-OS to tell how<br>they work.  Only way to know possibly would be to go into debug mode -- don't know if you want to try that or not.<br><br>I haven't run ASA much of late, but I do agree while CBAC / ZBFW just works, ya can't beat the ASA for security.<br><br>Regards]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27733025</guid>
<pubDate>Fri, 16 Nov 2012 02:49:12 EDT</pubDate>
</item>

<item>
<title>Re: ASA vs ZBFW</title>
<link>http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27733008</link>
<description><![CDATA[RyanG1 posted : well ive come to the conclusion that this must be some inherent difference in how its handling the connections that cannot be duplicated with ZBFW... or.... the asa is causing a false positive....im leaning towards this one but i dont have evidence to support it one way or the other...<br><br>Ryan<br><small>--<br>Human beings, who are almost unique in having the ability to learn from the experience of others, are also remarkable for their apparent disinclination to do so. -Douglas Adams</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27733008</guid>
<pubDate>Fri, 16 Nov 2012 02:03:53 EDT</pubDate>
</item>

<item>
<title>Re: ASA vs ZBFW</title>
<link>http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27723318</link>
<description><![CDATA[RyanG1 posted : yea if i do a port forward it reports Open on the one but the others report strict. Im really not even trying to do this to fix the handful of xboxs in the house... its more so to understand what the difference is. Im also kinda of wondering if the ASA is tricking the xbox service into thinking the connection is open... but im not sure and i have no evidence to support it. I personally believe the ASA is superior to ZFW but that's a biased opinion =p<br><br>Heres the ZFW config:<br><pre class="brush: text">ip access-list extended acl_all_protocols_v4&#012; permit gre any any&#012; permit tcp any any&#012; permit udp any any&#012; permit icmp any any&#012;ip access-list extended acl_fw_fpx_outside_in&#012; permit icmp any any&#012; permit tcp any any established&#012; permit tcp any eq bgp any&#012; permit tcp any any eq bgp&#012; deny   ip any any&#012;ip access-list extended acl_fw_outside_ports_in&#012; permit tcp any any eq 9990&#012; permit tcp any any range 5500 5510&#012; permit tcp any any eq 4490&#012; permit tcp any any eq 3389&#012; permit udp any any gt 1024&#012; permit tcp any any eq 3074&#012; permit udp any any eq 88&#012;class-map type inspect match-any cmap_all_protocols&#012; match access-group name acl_all_protocols_v6&#012; match access-group name acl_all_protocols_v4&#012;class-map type inspect match-any cmap_outside_self_in&#012; match access-group name acl_fw_outside_self_in&#012;class-map match-any cmap_qos_bw_high&#012; match access-group name acl_qos_bw_high&#012;class-map match-any cmap_qos_bw_low&#012; match access-group name acl_qos_bw_low&#012;class-map match-any cmap_qos_bw_med&#012; match access-group name acl_qos_bw_med&#012;class-map match-any cmap_police_bw_ftps&#012; match access-group name acl_police_bw_ftps&#012;class-map type inspect match-any cmap_outside_ports_in&#012; match access-group name acl_fw_outside_ports_in&#012;class-map match-any cmap_qos_bw_other&#012; match access-group name acl_qos_bw_other&#012;class-map type inspect match-any cmap_fpx_outside_in&#012; match access-group name acl_fw_fpx_outside_in&#012; match access-group name acl_fw_fpx_outside_in_v6&#012;class-map match-any cmap_qos_priority&#012; description priority traffic queue&#012; match access-group name acl_qos_priority&#012;class-map type inspect match-any cmap_fpx_in&#012; match access-group name fpx_in&#012;!&#012;!&#012;policy-map type inspect Inside2FPX-Outside&#012; class type inspect cmap_all_protocols&#012;  inspect&#012; class class-default&#012;  drop log&#012;policy-map type inspect FPX-Outside2Inside&#012; class type inspect cmap_fpx_outside_in&#012;  inspect&#012; class class-default&#012;  drop log&#012;policy-map type inspect Inside2Outside&#012; class type inspect cmap_all_protocols&#012;  inspect &#012; class class-default&#012;  drop log&#012;policy-map type inspect Outside2Inside&#012; class type inspect cmap_outside_ports_in&#012;  inspect &#012; class type inspect cmap_all_protocols&#012;  inspect &#012; class class-default&#012;  drop log&#012;policy-map type inspect Outside2Self&#012; class type inspect cmap_outside_self_in&#012;  inspect &#012; class class-default&#012;  drop log&#012;policy-map type inspect Self2Outside&#012; class type inspect cmap_all_protocols&#012;  inspect &#012; class class-default&#012;  drop log&#012;  &#012;zone security inside&#012; description inside zone&#012;zone security outside&#012; description outside zone&#012;zone security FPX-Outside&#012; description fpx tunnel&#012;zone-pair security Inside2Outside source inside destination outside&#012; service-policy type inspect Inside2Outside&#012;zone-pair security Outside2Inside source outside destination inside&#012; service-policy type inspect Outside2Inside&#012;zone-pair security Inside2FPX-Outside source inside destination FPX-Outside&#012; service-policy type inspect Inside2FPX-Outside&#012;zone-pair security FPX-Outside2Inside source FPX-Outside destination inside&#012; service-policy type inspect FPX-Outside2Inside&#012; &#012;</pre><!--end code block--><br>Heres the ASA config:<br><pre class="brush: text">: Saved&#012;: Written by ryan.sa at 19:05:51.106 cdt Fri Nov 2 2012&#012;!&#012;ASA Version 8.2(5)6 &#012;!&#012;hostname fw-nat1&#012;enable password 8Ry2YjIyt7RRXU24 encrypted&#012;passwd 2KFQnbNIdI.2KYOU encrypted&#012;names&#012;!&#012;interface Ethernet0/0&#012; description to modem&#012; switchport access vlan 99&#012;!&#012;interface Ethernet0/1&#012; switchport access vlan 100&#012;!&#012;interface Ethernet0/2&#012; switchport access vlan 100&#012;!&#012;interface Ethernet0/3&#012;shutdown&#012;!&#012;interface Ethernet0/4&#012; shutdown&#012;!&#012;interface Ethernet0/5&#012; shutdown&#012;!&#012;interface Ethernet0/6&#012; shutdown&#012;!&#012;interface Ethernet0/7&#012; shutdown&#012;!&#012;interface Vlan1&#012; no nameif&#012; no security-level&#012; no ip address&#012;!&#012;interface Vlan99&#012; nameif outside&#012; security-level 0&#012; ip address dhcp setroute&#012;!&#012;interface Vlan100&#012; description to managed gig switch&#012; nameif inside&#012; security-level 100&#012; ip address 192.168.6.1 255.255.255.248 &#012; ospf hello-interval 1&#012; ospf dead-interval 3&#012;!&#012;boot system disk0:/asa825-6-k8.bin&#012;ftp mode passive&#012;clock timezone cst -6&#012;clock summer-time cdt recurring&#012;same-security-traffic permit inter-interface&#012;same-security-traffic permit intra-interface&#012;object-group service outside_allow_ports_in&#012; service-object tcp eq 5500 &#012; service-object tcp eq 5501 &#012; service-object tcp eq 5502 &#012; service-object tcp eq 5503 &#012; service-object tcp eq 5504 &#012; service-object tcp eq 5505 &#012; service-object tcp eq 5506 &#012; service-object tcp eq 5507 &#012; service-object tcp eq 5508 &#012; service-object tcp eq 5509 &#012; service-object tcp eq 5510 &#012; service-object tcp eq 3074 &#012; service-object tcp eq 9990 &#012; service-object gre &#012; service-object 41 &#012; service-object udp gt 1024 &#012; service-object esp &#012; service-object udp eq 4500 &#012; service-object udp eq isakmp &#012; service-object tcp eq 4490 &#012; service-object tcp eq 4491 &#012; service-object tcp eq 4489 &#012; service-object tcp eq 25565&#012; service-object tcp range 6784 6786 &#012;object-group network deny-ip-in&#012; network-object host 187.114.255.224&#012; network-object 0.0.0.0 255.0.0.0&#012; network-object 127.0.0.0 255.0.0.0&#012; network-object 169.254.0.0 255.255.0.0&#012; network-object 192.0.0.0 255.255.255.0&#012; network-object 192.0.2.0 255.255.255.0&#012; network-object 198.18.0.0 255.254.0.0&#012; network-object 198.51.100.0 255.255.255.0&#012; network-object 203.0.113.0 255.255.255.0&#012; network-object 224.0.0.0 240.0.0.0&#012; network-object 240.0.0.0 240.0.0.0&#012; network-object host 166.87.181.113&#012;object-group icmp-type icmp-allowed&#012; description "default ICMP types allowed"&#012; icmp-object echo-reply&#012; icmp-object unreachable&#012; icmp-object echo&#012; icmp-object time-exceeded&#012; icmp-object traceroute&#012;access-list nat_acl extended permit ip 192.168.10.0 255.255.255.0 any &#012;access-list nat_acl extended permit ip 192.168.11.0 255.255.255.0 any &#012;access-list nat_acl extended permit ip 192.168.6.0 255.255.255.0 any &#012;access-list outside_in extended deny ip any object-group deny-ip-in log &#012;access-list outside_in extended deny ip object-group deny-ip-in any log &#012;access-list outside_in extended permit icmp any any object-group icmp-allowed &#012;access-list outside_in extended permit ip 192.168.6.248 255.255.255.248 192.168.10.0 255.255.255.0 &#012;access-list outside_in extended permit object-group outside_allow_ports_in any any &#012;access-list outside_in extended deny tcp any any log &#012;access-list outside_in extended deny udp any any log &#012;access-list outside_in extended deny ip any any log &#012;access-list nonat extended permit ip 192.168.10.0 255.255.255.0 host 172.32.2.1 &#012;access-list nonat extended permit ip 192.168.10.0 255.255.255.0 192.168.6.0 255.255.255.0 &#012;access-list nonat extended permit ip 192.168.10.0 255.255.255.0 192.168.237.0 255.255.255.0 &#012;access-list nonat extended permit ip 192.168.6.0 255.255.255.248 host 172.32.2.1 &#012;access-list nonat extended permit ip 192.168.6.0 255.255.255.248 host 172.31.2.1 &#012;access-list nonat extended permit ip 192.168.237.0 255.255.255.0 192.168.6.0 255.255.255.0 &#012;access-list nonat extended permit ip 192.168.6.0 255.255.255.0 192.168.237.0 255.255.255.0 &#012;access-list acl-qos-rdp extended permit tcp any any eq 3389 &#012;access-list acl-qos-rdp extended permit tcp any any eq 4489 &#012;access-list acl-qos-rdp extended permit tcp any any eq 4490 &#012;access-list acl-qos-rdp extended permit tcp any eq 3389 any &#012;access-list acl-qos-rdp extended permit tcp any eq 4489 any &#012;access-list acl-qos-rdp extended permit tcp any eq 4490 any &#012;access-list acl-qos-rdp extended permit tcp any eq 4491 any &#012;access-list acl-qos-xboxlive extended permit udp any any eq 3074 &#012;access-list acl-qos-halflife extended permit udp any any range 27000 27500 &#012;access-list torrent_conn_limit extended permit udp any gt 28000 any &#012;access-list torrent_conn_limit extended permit udp any any gt 28000 &#012;access-list torrent_conn_limit extended permit tcp any any gt 28000 &#012;access-list acl-qos-ip extended permit ip any host 4.2.2.2 &#012;access-list acl-qos-ip extended permit ip any host 50.56.228.65 &#012;access-list acl-qos-ip extended permit ip host 50.56.228.65 any &#012;access-list acl-qos-ftps extended permit tcp any range 5500 5510 any &#012;access-list CLIENTVPN extended permit ip 192.168.10.0 255.255.255.0 192.168.237.0 255.255.255.0&#012;access-list CLIENTVPN extended permit ip 192.168.6.0 255.255.255.0 192.168.237.0 255.255.255.0 &#012;access-list nat_acl_outside extended permit ip 192.168.237.0 255.255.255.0 any &#012;access-list ipsec11 extended permit ip 192.168.6.0 255.255.255.248 host 172.32.2.1 &#012;access-list ipsec11 extended permit gre 192.168.6.0 255.255.255.248 host 172.32.2.1 &#012;access-list inside_in extended permit ip any any &#012;access-list ipsec12 extended permit ip 192.168.6.0 255.255.255.248 host 172.31.2.1 &#012;access-list ipsec12 extended permit gre 192.168.6.0 255.255.255.248 host 172.31.2.1 &#012;access-list LABVPN extended permit ip host 192.168.10.254 192.168.237.0 255.255.255.0 &#012;pager lines 24&#012;logging enable&#012;logging timestamp&#012;logging buffer-size 8192&#012;logging buffered notifications&#012;logging trap warnings&#012;logging history warnings&#012;logging host inside 192.168.10.254&#012;logging message 302014 level debugging&#012;flow-export destination inside 192.168.10.254 2055&#012;flow-export template timeout-rate 1&#012;flow-export delay flow-create 60&#012;mtu outside 1500&#012;mtu inside 1500&#012;ip local pool IPPOOL 192.168.237.1-192.168.237.254 mask 255.255.255.0&#012;no failover&#012;icmp unreachable rate-limit 10 burst-size 5&#012;icmp deny any outside&#012;asdm image disk0:/asdm-523.bin&#012;no asdm history enable&#012;arp timeout 14400&#012;global (outside) 1 interface&#012;nat (outside) 1 access-list nat_acl_outside&#012;nat (inside) 0 access-list nonat&#012;nat (inside) 1 access-list nat_acl&#012;static (inside,outside) tcp interface 4491 192.168.10.254 3389 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 9990 192.168.10.254 9990 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5500 192.168.10.254 5500 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5501 192.168.10.254 5501 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5502 192.168.10.254 5502 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5503 192.168.10.254 5503 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5504 192.168.10.254 5504 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5505 192.168.10.254 5505 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5506 192.168.10.254 5506 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5507 192.168.10.254 5507 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5508 192.168.10.254 5508 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5509 192.168.10.254 5509 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 5510 192.168.10.254 5510 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 25565 192.168.10.254 25565 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 6784 192.168.10.101 6784 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 6785 192.168.10.101 6785 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 6786 192.168.10.101 6786 netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 4490 192.168.10.101 3389 netmask 255.255.255.255 &#012;access-group outside_in in interface outside&#012;access-group inside_in in interface inside&#012;!&#012;!&#012;router ospf 2004&#012; network 192.168.6.0 255.255.255.248 area 11&#012; log-adj-changes&#012; default-information originate metric-type 1&#012;!&#012;timeout xlate 3:00:00&#012;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&#012;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&#012;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&#012;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&#012;timeout tcp-proxy-reassembly 0:01:00&#012;timeout floating-conn 0:00:00&#012;dynamic-access-policy-record DfltAccessPolicy&#012;aaa-server radius-auth protocol radius&#012; reactivation-mode timed&#012;aaa-server radius-auth (inside) host 192.168.10.253&#012; key test&#012;aaa-server TACACS+ protocol tacacs+&#012; reactivation-mode timed&#012;aaa-server TACACS+ (inside) host 192.168.10.253&#012; timeout 2&#012; key ZaQ1@wSx#&#012;aaa authentication http console LOCAL &#012;aaa authentication telnet console LOCAL &#012;aaa authentication ssh console TACACS+ LOCAL&#012;aaa authentication enable console TACACS+ LOCAL&#012;aaa authorization command LOCAL &#012;http server enable 8443&#012;http 192.168.10.0 255.255.255.0 inside&#012;snmp-server host inside 192.168.10.254 poll community home.lan! version 2c&#012;no snmp-server location&#012;no snmp-server contact&#012;snmp-server community home.lan!&#012;snmp-server enable traps snmp authentication linkup linkdown coldstart&#012;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &#012;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &#012;crypto ipsec transform-set ESP-AES-SHA esp-aes esp-sha-hmac &#012;crypto ipsec security-association lifetime seconds 28800&#012;crypto ipsec security-association lifetime kilobytes 4608000&#012;crypto dynamic-map home 65535 set transform-set ESP-AES-SHA&#012;crypto dynamic-map home 65535 set reverse-route&#012;crypto map ipsec-vpn 11 match address ipsec11&#012;crypto map ipsec-vpn 11 set peer 108.166.74.130 &#012;crypto map ipsec-vpn 11 set transform-set ESP-3DES-SHA ESP-3DES-MD5 ESP-AES-SHA&#012;crypto map ipsec-vpn 11 set reverse-route&#012;crypto map ipsec-vpn 12 match address ipsec12&#012;crypto map ipsec-vpn 12 set peer 198.101.196.211 &#012;crypto map ipsec-vpn 12 set transform-set ESP-3DES-SHA ESP-3DES-MD5 ESP-AES-SHA&#012;crypto map ipsec-vpn 12 set reverse-route&#012;crypto map ipsec-vpn 65535 ipsec-isakmp dynamic home&#012;crypto map ipsec-vpn interface outside&#012;crypto isakmp identity address &#012;crypto isakmp enable outside&#012;crypto isakmp policy 10&#012; authentication pre-share&#012; encryption 3des&#012; hash sha&#012; group 2&#012; lifetime 86400&#012;crypto isakmp policy 12&#012; authentication pre-share&#012; encryption aes&#012; hash sha&#012; group 2&#012; lifetime 86400&#012;crypto isakmp policy 15&#012; authentication pre-share&#012; encryption 3des&#012; hash md5&#012; group 5&#012; lifetime 86400&#012;telnet timeout 15&#012;ssh 192.168.237.0 255.255.255.0 outside&#012;ssh 192.168.10.0 255.255.255.0 inside&#012;ssh 192.168.11.0 255.255.255.0 inside&#012;ssh 192.168.237.0 255.255.255.0 inside&#012;ssh 192.168.6.0 255.255.255.248 inside&#012;ssh timeout 15&#012;console timeout 5&#012;management-access inside&#012; &#012;priority-queue outside&#012;  queue-limit   300&#012;  tx-ring-limit 128&#012;no threat-detection rate scanning-threat rate-interval 600 average-rate 5 burst-rate 10&#012;no threat-detection rate scanning-threat rate-interval 3600 average-rate 4 burst-rate 8&#012;threat-detection rate scanning-threat rate-interval 600 average-rate 15 burst-rate 30&#012;threat-detection rate scanning-threat rate-interval 3600 average-rate 12 burst-rate 24&#012;threat-detection basic-threat&#012;threat-detection scanning-threat shun except ip-address 192.168.10.0 255.255.255.0&#012;threat-detection scanning-threat shun duration 7200&#012;threat-detection statistics access-list&#012;no threat-detection statistics tcp-intercept&#012;ntp server 192.168.10.254 source inside prefer&#012;username enable15 password 1fU1phQraSx9fmtJ encrypted privilege 15&#012;tunnel-group 108.166.74.130 type ipsec-l2l&#012;tunnel-group 108.166.74.130 ipsec-attributes&#012; pre-shared-key test&#012;class-map qos-halflife&#012; match access-list acl-qos-halflife&#012;class-map qos-ftps&#012; match access-list acl-qos-ftps&#012;class-map qos-ip&#012; match access-list acl-qos-ip&#012;class-map qos-xboxlive&#012; match access-list acl-qos-xboxlive&#012;class-map cmap_torrent_conn_limit&#012; match access-list torrent_conn_limit&#012;class-map qos-rdp&#012; match access-list acl-qos-rdp&#012;class-map inspection_default&#012; match default-inspection-traffic&#012;class-map global_class&#012; match access-list global_mpc&#012;!&#012;!&#012;policy-map type inspect dns preset_dns_map&#012; parameters&#012;  message-length maximum client auto&#012;  message-length maximum 4096&#012;policy-map qos_traffic_policy&#012; class qos-xboxlive&#012;  priority&#012; class qos-halflife&#012;  priority&#012; class qos-ip&#012;  priority&#012; class qos-rdp&#012;  priority&#012;policy-map inside_policy&#012; class cmap_torrent_conn_limit&#012;  set connection per-client-max 3072 &#012;  set connection timeout embryonic 0:00:10 &#012;  set connection decrement-ttl&#012; class class-default&#012;policy-map global_policy&#012; class inspection_default&#012;  inspect dns preset_dns_map &#012;  inspect ftp &#012;  inspect h323 h225 &#012;  inspect h323 ras &#012;  inspect netbios &#012;  inspect rsh &#012;  inspect rtsp &#012;  inspect esmtp &#012;  inspect tftp &#012;  inspect sip  &#012;  inspect http &#012;  inspect icmp &#012;  inspect ip-options &#012; class class-default&#012;  set connection decrement-ttl&#012;policy-map outside_policy&#012; class qos-ftps&#012;  police output 4096000&#012; class class-default&#012;  shape average 4960000&#012;  service-policy qos_traffic_policy&#012;!&#012;service-policy global_policy global&#012;service-policy outside_policy interface outside&#012;service-policy inside_policy interface inside&#012;privilege show level 1 mode exec command running-config&#012;prompt hostname domain &#012;no call-home reporting anonymous&#012;call-home&#012; profile CiscoTAC-1&#012;  no active&#012;  destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService&#012;  destination address email callhome@cisco.com&#012;  destination transport-method http&#012;  subscribe-to-alert-group diagnostic&#012;  subscribe-to-alert-group environment&#012;  subscribe-to-alert-group inventory periodic monthly&#012;  subscribe-to-alert-group configuration periodic monthly&#012;  subscribe-to-alert-group telemetry periodic daily&#012;Cryptochecksum:423d1d15db9feac71b1ef6f3979c544d&#012;: end&#012; &#012;</pre><!--end code block--><br><small>--<br>Human beings, who are almost unique in having the ability to learn from the experience of others, are also remarkable for their apparent disinclination to do so. -Douglas Adams</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27723318</guid>
<pubDate>Tue, 13 Nov 2012 13:25:44 EDT</pubDate>
</item>

<item>
<title>Re: ASA vs ZBFW</title>
<link>http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27721775</link>
<description><![CDATA[HELLFIRE posted : Can you post the ZBFW config for review?<br><br>Also, I know there's nothing to 'configure' in terms of the ASA 'firewall,' but if possible could you also post<br>that as well?<br><br>Off the top of my head, I've never figured out what / how MS determines strict NAT versus moderate NAT versas any NAT...<br>NAT is nat, from a network perspective.  From what little I've read about getting XBOX to work with a non-UPNP<br>router config-wise is no different than the port-forwarded days of yore, and AFAIK, both ASA (the Adaptive Security<br>ALGORITHM) and ZBFW are intrinsically stateful, so all the XBOX should have to do is say 'ASA / ZBFW, I am making<br>a connection to x.x.x.x on port yyy."<br><br>My 00000010bits.<br><br>Regards]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-ASA-vs-ZBFW-27721775</guid>
<pubDate>Tue, 13 Nov 2012 02:18:26 EDT</pubDate>
</item>

<item>
<title>ASA vs ZBFW</title>
<link>http://www.dslreports.com/forum/ASA-vs-ZBFW-27720156</link>
<description><![CDATA[RyanG1 posted : So i have an 891 doing ZBFW and a handful of xboxes behind them (no port forwarding) and im getting the expected issues where 1 is showing moderate and the others show strict for the nat type. The interesting part of this issue is that the ASA that was in its place had no port forwarding either but the nat type showed as open (as if it was correctly port forwarded). <br><br>Now i know the ASA does not support UPNP and i cannot quite figure out this behavior. Ive tried to duplicate it in the ZBFW config but it does not work compared to the asa config. <br><br>Just wondering if anyone has any thoughts on this when comparing the stateful firewalls of the ASA and IOS' ZBFW.<br><br>Ryan<br><small>--<br>Human beings, who are almost unique in having the ability to learn from the experience of others, are also remarkable for their apparent disinclination to do so. -Douglas Adams</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/ASA-vs-ZBFW-27720156</guid>
<pubDate>Mon, 12 Nov 2012 15:44:53 EDT</pubDate>
</item>

</channel>
</rss>
