Personal Stateful Firewall Overview
▀ How Personal Stateful Firewall Works
▄ Cisco ASR 5000 Series Product Overview
OL-22938-02
If the AAA/OCS sends the SN-Firewall-Policy AVP with the string ―disable‖, the locally configured firewall
policy does not get applied.
If the SN-Firewall-Policy AVP is received with the string ―NULL‖, the existing policy will continue.
If the SN-Firewall-Policy AVP is received with a name that is not configured locally, the subscriber session is
terminated.
Mid-session Firewall Policy Update
The Firewall-and-NAT policy can be updated mid-session provided firewall policy was enabled during call setup.
Important:
When the firewall AVP contains ―disable‖ during mid-session firewall policy change, there will be
no action taken as the Firewall-and-NAT policy cannot be disabled dynamically. The policy currently applied will
continue.
Important:
When a Firewall-and-NAT policy is deleted, for all subscribers using the policy, Firewall processing
is disabled, also ECS sessions for the subscribers are dropped. In case of session recovery, the calls are recovered but
with Stateful Firewall disabled.
How it Works
The following figures illustrate packet flow in Stateful Firewall processing for a subscriber.
Содержание ASR 5000 Series
Страница 1: ......
Страница 26: ......
Страница 48: ...New In Release 10 0 SCM Features Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 50: ......
Страница 58: ......
Страница 67: ...Product Service and Feature Licenses Default Licenses Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 68: ......
Страница 126: ......
Страница 138: ......
Страница 146: ......
Страница 218: ......
Страница 236: ......
Страница 356: ......
Страница 374: ......
Страница 422: ......
Страница 496: ......
Страница 572: ......
Страница 654: ......
Страница 700: ......
Страница 726: ......
Страница 784: ......
Страница 816: ......
Страница 839: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 841: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 844: ......
Страница 906: ......
Страница 926: ......
Страница 942: ......
Страница 943: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 30 Technical Specifications ...
Страница 966: ......
Страница 967: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 31 Safety Electrical and Environmental Certifications ...
Страница 972: ......