Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Part 6 : Test Firewall Functionality from IN - ZONE to OUT - ZONE Verify that internal hosts can still access external resources after configuring
Part : Test Firewall Functionality from INZONE to OUTZONE
Verify that internal hosts can still access external resources after configuring the ZPF
Step : From internal PCC ping the external PCA server.
From the PCC command prompt, ping PCA at The ping should succeed.
Step : From internal PCC SSH to the R S interface.
a From the PCC command prompt, SSH to R at Use the username Admin and the password Adminpa to access R The SSH session should succeed.
b While the SSH session is active, issue the command show policymap type inspect zonepair sessions on R to view established sessions.
R# show policymap type inspect zonepair sessions
policy exists on zp INOUTZPAIR
Zonepair: INOUTZPAIR
Servicepolicy inspect : INOUTPMAP
Classmap: INNETCLASSMAP matchall
Match: accessgroup
Inspect
Number of Established Sessions
Established Sessions
Session :: tcp SISOPENTCPESTAB
Created :: Last heard ::
Bytes sent initiator:responder:
Classmap: classdefault matchany
Match: any
Drop default action
packets, bytes
What is the source IP address and port number?
:port is random
What is the destination IP address and port number?
:SSH port
Step : From PCC exit the SSH session on R and close the command prompt window.
Step : From internal PCC open a web browser to the PCA server web page.
Enter the server IP address in the browser URL field, and click Go The HTTP session should succeed. While the HTTP session is active, issue the command show policymap type inspect zonepair sessions on R to view established sessions.
Note: If the HTTP session times out before you execute the command on R you will have to click the Go button on PCC to generate a session between PCC and PCA
R# show policymap type inspect zonepair sessions
policy exists on zp INOUTZPAIR
Zonepair: INOUTZPAIR
Servicepolicy inspect : INOUTPMAP
Classmap: INNETCLASSMAP matchall
Match: accessgroup
Inspect
Number of Established Sessions
Established Sessions
Session :: tcp SISOPENTCPESTAB
Created :: Last heard ::
Bytes sent initiator:responder:
Classmap: classdefault matchany
Match: any
Drop default action
packets, bytes
What is the source IP address and port number?
:port is random
What is the destination IP address and port number?
:HTTP web port
Step : Close the browser on PCC
Part : Test Firewall Functionality from OUTZONE to INZONE
Verify that external hosts CANNOT access internal resources after configuring the ZPF
Step : From the PCA server command prompt, ping PCC
From the PCA command prompt, ping PCC at The ping should fail.
Step : From R ping PCC
From R ping PCC at The ping should fail.
Step : Check results.
Your completion percentage should be Click Check Results to see feedback and verification of which required components have been completed.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started