<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco IOS Zone Based Policy Firewall</title>
	<atom:link href="http://blogg.kvistofta.nu/cisco-ios-zone-based-policy-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogg.kvistofta.nu/cisco-ios-zone-based-policy-firewall/</link>
	<description>A Cisco Security-guy exploring the world</description>
	<lastBuildDate>Mon, 03 May 2010 22:24:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Jimmy Larsson</title>
		<link>http://blogg.kvistofta.nu/cisco-ios-zone-based-policy-firewall/comment-page-1/#comment-88</link>
		<dc:creator>Jimmy Larsson</dc:creator>
		<pubDate>Sat, 06 Feb 2010 13:46:21 +0000</pubDate>
		<guid isPermaLink="false">http://blogg.kvistofta.nu/?p=680#comment-88</guid>
		<description>Hi Dazzler!&lt;br&gt;&lt;br&gt;Thanks for notifying me about the typo, it´s corrected now!&lt;br&gt;&lt;br&gt;Next step is to also do deep packet inspection in the same config. Like &quot;also, inside users should be able to http to internet, except to sites with the string &quot;piratebay&quot; in the url. Or something. ;)</description>
		<content:encoded><![CDATA[<p>Hi Dazzler!</p>
<p>Thanks for notifying me about the typo, it´s corrected now!</p>
<p>Next step is to also do deep packet inspection in the same config. Like &#8220;also, inside users should be able to http to internet, except to sites with the string &#8220;piratebay&#8221; in the url. Or something. <img src='http://blogg.kvistofta.nu/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jimmy Larsson</title>
		<link>http://blogg.kvistofta.nu/cisco-ios-zone-based-policy-firewall/comment-page-1/#comment-86</link>
		<dc:creator>Jimmy Larsson</dc:creator>
		<pubDate>Fri, 05 Feb 2010 22:29:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogg.kvistofta.nu/?p=680#comment-86</guid>
		<description>Thanks for the input. I have corrected it now.&lt;br&gt;&lt;br&gt;I was thinking about doing a third thing; a level7-inspection of something. Like &quot;Also, inside host should be able to http to urls except all .com-addresses&quot;. Hmm. Sounds like an idea for  next blog post.</description>
		<content:encoded><![CDATA[<p>Thanks for the input. I have corrected it now.</p>
<p>I was thinking about doing a third thing; a level7-inspection of something. Like &#8220;Also, inside host should be able to http to urls except all .com-addresses&#8221;. Hmm. Sounds like an idea for  next blog post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dazzler</title>
		<link>http://blogg.kvistofta.nu/cisco-ios-zone-based-policy-firewall/comment-page-1/#comment-85</link>
		<dc:creator>Dazzler</dc:creator>
		<pubDate>Fri, 05 Feb 2010 17:24:14 +0000</pubDate>
		<guid isPermaLink="false">http://blogg.kvistofta.nu/?p=680#comment-85</guid>
		<description>Cool example. I too had a hard job with this, especially trying to get it to work staeless as well as stateful..... &lt;br&gt;&lt;br&gt;One small typo, below the IP address should read 10.13.13.13.&lt;br&gt;&lt;br&gt;Task 2. Also allow specific pings outbound&lt;br&gt;The next task for me is to enable ping from inside hosts to the outside. To make it a bit trickier I decide to make an exception for the internal host 10.11.11.11 who should not be able to ping.&lt;br&gt;&lt;br&gt;Great work! :-)</description>
		<content:encoded><![CDATA[<p>Cool example. I too had a hard job with this, especially trying to get it to work staeless as well as stateful&#8230;.. </p>
<p>One small typo, below the IP address should read 10.13.13.13.</p>
<p>Task 2. Also allow specific pings outbound<br />The next task for me is to enable ping from inside hosts to the outside. To make it a bit trickier I decide to make an exception for the internal host 10.11.11.11 who should not be able to ping.</p>
<p>Great work! <img src='http://blogg.kvistofta.nu/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
