ZBF vs ASA vs FTD: Which Firewall Belongs Where
Zone-Based Firewall, ASA, and FTD solve different jobs. This comparison uses real command output captured from all three platforms to show you which Cisco firewall belongs where, not which one is best.
Hardening the network you already run. Articles tagged Network Security cover control-plane protection, access control, segmentation, and the attacks each countermeasure is actually stopping.
Zone-Based Firewall, ASA, and FTD solve different jobs. This comparison uses real command output captured from all three platforms to show you which Cisco firewall belongs where, not which one is best.
Flat ZBF policies do not scale. This post shows how nested class-maps let you reuse protocol groups across policies and combine match-all conditions with match-any protocols to build layered, maintainable firewall policy.
Your ZBF matches protocol http, but the app on TCP 8080 will not pass because the inspector cannot see it. Port-maps teach the IOS XE protocol inspector about non-standard ports. Real cat8000v output shows the failure and the fix.
The Zone-Based Firewall is the stateful firewall inside Cisco IOS XE. This anchor guide covers zones, zone-pairs, the class-map and policy-map model, and the default-drop trap that locks engineers out of their own routers.
Cisco removed Clientless SSL VPN (WebVPN) from the ASA in 9.17. Real 9.24 CLI proof, and the Secure Client remote-access VPN that replaced it.
EtherType ACLs let a transparent-mode Cisco ASA filter non-IP frames a routed firewall never sees. Learn what bridges through a Layer 2 firewall by default and how to control it.
Typing firewall transparent wipes the ASA's entire running configuration instantly. This walkthrough covers switching modes safely from the console with a saved config, then building a working transparent-mode firewall on the ASAv.
Connections that die crossing the ASA with no ACL deny are usually TCP normalization. You see the real tcp-map and accelerated-security-path drop counters from an ASAv 9.24 that turn this silent killer into something visible.
Build a custom Layer 7 HTTP inspection policy on the ASA that blocks a specific URL by regex, then prove it with a real before-and-after test: one URL loads instantly, the other hangs until timeout. Captured on an ASAv 9.24 in CML.
L3 and L4 filtering is half a firewall. This post shows the ASA's application inspection engines in action on a real ASAv 9.24 in CML, including the default inspection policy and live per-interface counters.
MPF is the engine under nearly every advanced ASA feature. Build class-maps, policy-maps, and service-policies from scratch on a real ASAv 9.24 in CML, with live counters climbing as a Linux client hits a published web server.
Build SNMPv3 in production form: users, groups, views, and the three security levels. The payoff is a real encrypted trap arriving and being decrypted on a Linux receiver, with no cleartext community strings on the wire.