ZBFW inspect Keyword

The type inspect keyword is essential in Zone-Based Firewall (ZBFW) configurations on Cisco IOS routers. It is used to enable stateful packet inspection, and it can be applied at different configuration levels such as class maps, policy maps, or within a class under a policy map. This setup allows the inspection of traffic at Layer 3, Layer 4, or Layer 7 of the OSI Model, based on defined parameters like protocol types, enabling traffic classification and inspection.

Regular policy maps differ from those that use the type inspect keywords as they are primarily used for Quality of Service (QoS) tasks such as traffic shaping, policing, and prioritization by classifying traffic to apply QoS actions like bandwidth management.

https://networklessons.com/cisco/ccie-routing-switching/zone-based-firewall-configuration-example/

Links to this page: