Cisco Zone Based Firewall and SDM

Hello,
Can someone please help us identify why we have multiple Cisco routers some with the ZBF on and some with the older firewalling feature within SDM.  I think it is something to do with the version of the IOS or the version of the SDM but I cannot find anything from Cisco which explains why we have these differences,
Can someone help please?
Thanks!
nmxsupportAsked:
Who is Participating?
 
mr_dirtConnect With a Mentor Commented:
SDM started supporting Zone FW in version 2.3, if I recall correctly.  If you use a version of SDM that supports Zone Firewall to configure a router with IOS that includes Zone FW (12.4(6)T or later), SDM will default to configuring a Zone Firewall, unless there is existing CBAC ('ip inspect'/old-style configuration).  In cases where CBAC is in the router already, SDM will continue configuring CBAC CLI.
0
 
Ilir MitrushiIT Infrastructure and Security ArchitectCommented:
it may be that you have old ios images which do not support zbf. mixing zbf with cbac is  not recommended. have a look here
http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a008060f6dd.html#wp1047648
0
 
nmxsupportAuthor Commented:
okay thanks for the information - cisco couldn't give us any information on this.
0
 
mr_dirtCommented:
Sorry, I incorrectly posted that SDM first supported Zone FW in 2.3.  Zone FW support was introduced in SDM in 2.4:

http://download-sj.cisco.com/cisco/web/sdm/SDMv2.4-Readme.html#56197
0
All Courses

From novice to tech pro — start learning today.