Re: Zone Based firewall comment

From: Narbik Kocharians <narbikk_at_gmail.com>
Date: Mon, 28 Feb 2011 00:12:09 -0800

Knowing the ins and outs of the ZBFW will NOT hurt, but i doubt that they
will hit you with every options. If this was a Security lab that you were
going to take, i would say YES, KNOW ALL THE OPTIONS, but in R&S.....i doubt
that they will do that.

On Sun, Feb 27, 2011 at 10:44 PM, Chris Proctor <chris_at_cwproctor.net> wrote:

> Well, after beating my head against this for awhile I have come to three
> conclusions (call it venting if you will):
> 1.) Security zones are cool
> 2.) Inspect maps are overly complex pieces of crap
> 3.) Specialized inspect maps are even bigger pieces of crap
>
> I find myself hoping they won't get too carried away with this subject.
> Working out all of the possible regex's, etc and nesting of relationships
> could easily take me 20 hours for a complex enough configuration. Can
> anyone tell me if I'm wasting my time going through the lower levels of hell
> here?
>
> --
> Chris Proctor
>
>
> --
> This message was scanned by ESVA and is believed to be clean.
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
>
>
>
>
>
>
>
>

-- 
*Narbik Kocharians
*CCSI#30832, CCIE# 12410 (R&S, SP, Security)
www.MicronicsTraining.com <http://www.micronicstraining.com/>
Sr. Technical Instructor
*Ask about our FREE Lab Voucher with our Boot Camps*
YES! We take Cisco Learning Credits!
Training & Remote Racks available
Blogs and organic groups at http://www.ccie.net
Received on Mon Feb 28 2011 - 00:12:09 ART

This archive was generated by hypermail 2.2.0 : Tue Mar 01 2011 - 07:01:50 ART