C H A P T E R
44-1
Cisco 7600 Series Router Cisco IOS Software Configuration Guide, Release 12.2SX
OL-4266-08
44
Configuring the Cisco IOS Firewall Feature Set
This chapter describes how to configure the Cisco IOS firewall feature set on the Cisco 7600 series
routers. This chapter contains these sections:
•
Cisco IOS Firewall Feature Set Support Overview, page 44-1
•
Cisco IOS Firewall Guidelines and Restrictions, page 44-2
•
Additional CBAC Configuration, page 44-3
Tip
For additional information (including configuration examples and troubleshooting information), see the
documents listed on this page:
http://www.cisco.com/en/US/products/hw/routers/ps368/tsd_products_support_series_home.html
Cisco IOS Firewall Feature Set Support Overview
The firewall feature set images support these Cisco IOS firewall features:
•
Context-Based Access Control (CBAC) —The PFC installs entries in the NetFlow table to direct
flows that require CBAC to the MSFC where the CBAC is applied in software on the MSFC.
•
Authentication Proxy—After authentication on the MSFC, the PFC provides TCAM support for the
authentication policy.
•
Port-to-Application Mapping (PAM)—PAM is done in software on the MSFC.
For more information about Cisco IOS firewall features, refer to the following publications:
•
Cisco IOS Security Configuration Guide
, Release 12.2, “Traffic Filtering and Firewalls” chapter and
these sections:
–
“Cisco IOS Firewall Overview” at this URL:
http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_cfg_fwall_intrsn.html
–
“Configuring Context-Based Access Control” at this URL:
http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_cfg_content_ac.html
–
“Configuring Authentication Proxy” at this URL:
http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_cfg_authen_prxy.html
•
Cisco IOS Security Command Reference
publication at this URL: