Personal Stateful Firewall Overview
▀ How Personal Stateful Firewall Works
▄ Cisco ASR 5000 Series Product Overview
OL-22938-02
If the AAA/OCS sends the SN-Firewall-Policy AVP with the string ―disable‖, the locally configured firewall
policy does not get applied.
If the SN-Firewall-Policy AVP is received with the string ―NULL‖, the existing policy will continue.
If the SN-Firewall-Policy AVP is received with a name that is not configured locally, the subscriber session is
terminated.
Mid-session Firewall Policy Update
The Firewall-and-NAT policy can be updated mid-session provided firewall policy was enabled during call setup.
Important:
When the firewall AVP contains ―disable‖ during mid-session firewall policy change, there will be
no action taken as the Firewall-and-NAT policy cannot be disabled dynamically. The policy currently applied will
continue.
Important:
When a Firewall-and-NAT policy is deleted, for all subscribers using the policy, Firewall processing
is disabled, also ECS sessions for the subscribers are dropped. In case of session recovery, the calls are recovered but
with Stateful Firewall disabled.
How it Works
The following figures illustrate packet flow in Stateful Firewall processing for a subscriber.
Summary of Contents for ASR 5000 Series
Page 1: ......
Page 26: ......
Page 48: ...New In Release 10 0 SCM Features Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Page 50: ......
Page 58: ......
Page 68: ......
Page 126: ......
Page 138: ......
Page 146: ......
Page 218: ......
Page 236: ......
Page 356: ......
Page 374: ......
Page 422: ......
Page 496: ......
Page 572: ......
Page 654: ......
Page 700: ......
Page 726: ......
Page 784: ......
Page 816: ......
Page 844: ......
Page 906: ......
Page 926: ......
Page 942: ......
Page 943: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 30 Technical Specifications ...
Page 966: ......
Page 972: ......