The IOS Zone-Based Firewall first showed up in 12.4(6)T and the goal was to provide an intuitive
and straightforward policy design approach for multiple interface routers. There was also a desire
to offer a greater level of granularity for the application of such policies. The Zone-Based approach
utilizes
CBAC technology and gives you everything you had there, plus more.

In order to configure the Zone-Based Firewall, you define your zones, define your class maps,
define your policy maps, and then define your zone pairs and apply your policy maps to them.
Possible actions for traffic moving between zones is INSPECT, DROP, or PASS. Zone Drop or Pass?

Inspect causes the traffic to be monitored with the IOS stateful packet inspection (think CBAC),
while drop and pass are obvious.
Pass allows the traffic to move between zones with no inspection whatsoever
.

Step 1: Define and populate our zones:

configure terminal
!
zone security ZONE_PRIVATE
zone security ZONE_INTERNET

!
interface range fa0/0
description LAN
zone-member security ZONE_PRIVATE
!
interface s0/0
description WAN
zone-member security ZONE_INTERNET

Step 2: Define the class maps that identify traffic that is
permitted between zones
:

configure terminal
!
class-map type inspect match-any INTERNET_TRAFFIC
match protocol http
match protocol https
match protocol ftp
match protocol smtp
match protocol pop3
match protocol dns
match protocol ssh
match protocol icmp
match protocol cifs
match protocol echo
match protocol ntp
match protocol bittorrent
match protocol bootpc
match protocol bootps
match protocol rtsp
match protocol vdolive

Step 3: Configure a policy map which specifies the action for the
class map
:

configure terminal
!
policy-map type inspect PRIVATE_TO_INTERNET
class type inspect INTERNET_TRAFFIC
inspect

Step 4: Configure the zone pair and apply your policy:

configure terminal
!
zone-pair security ZONE_PRIVATE_INT source ZONE_PRIVATE destination ZONE_INTERNET
service-policy type inspect PRIVATE_TO_INTERNET

Notice how this simple configuration allows for the stateful inspection of our
Internet protocols from the private areas to the  Internet.
It also blocks traffic from the Internet heading to the private area unless it is
in response to the inspected traffic

My Configuration in Place :

ip inspect max-incomplete high 900
ip inspect max-incomplete low 800
ip inspect one-minute high 900
ip inspect one-minute low 800
ip inspect udp idle-time 15
ip inspect dns-timeout 10
ip inspect tcp idle-time 900

!
!
zone security inside_zone
zone security outside_zone
zone security dmz_zone
zone security multimedia_zone
zone security voip_zone
zone security peripheral_zone

!
!
class-map type inspect match-any IN_OUT
match protocol http
match protocol https
match protocol ftp
match protocol smtp
match protocol pop3
match protocol bootpc

match protocol bootps
match protocol icmp
match protocol msnmsgr
match protocol ntp

match protocol ssh
match protocol telnet
match protocol cifs
match protocol dns
match protocol tcp
match access-group name WORKSTATION_NAT
match access-group name PC-techAPDMZ_NAT

!
policy-map type inspect IN_OUT
class type inspect IN_OUT
inspect
class class-default
drop

!
zone-pair security IN->OUT source inside_zone destination outside_zone
service-policy type inspect IN_OUT

!
!
class-map type inspect match-any VOIP_OUT
match protocol udp
match access-group name VOIP_NAT

!
policy-map type inspect VOIP_OUT
class type inspect VOIP_OUT
inspect
class class-default
drop

!
zone-pair security VOIP->OUT source voip_zone destination outside_zone
service-policy type inspect VOIP_OUT

!
!
class-map type inspect match-any DMZ_OUT
match protocol http
match protocol https
match protocol ftp
match access-group name DMZ_NAT

!
policy-map type inspect DMZ_OUT
class type inspect DMZ_OUT
inspect
class class-default
drop

!
zone-pair security DMZ->OUT source dmz_zone destination outside_zone
service-policy type inspect DMZ_OUT

!
!
class-map type inspect match-any MULTIMEDIA_OUT
match protocol bittorrent
match protocol http
match protocol https
match protocol ftp
match protocol echo
match protocol smtp
match protocol pop3

match protocol icmp
match protocol pptp
match protocol tcp
match protocol udp
match access-group name MULTIMEDIA_NAT

!
policy-map type inspect MULTIMEDIA_OUT
class type inspect MULTIMEDIA_OUT
inspect
class class-default
drop

!
zone-pair security MULTIMEDIA->OUT source multimedia_zone destination outside_zone
service-policy type inspect MULTIMEDIA_OUT

!
!
class-map type inspect match-any IN_MULTIMEDIA
match protocol cifs
match protocol tcp
match access-group name WORKSTATION_NAT

!
policy-map type inspect IN_MULTIMEDIA
class type inspect IN_MULTIMEDIA
inspect
class class-default
drop

!
zone-pair security IN->MULTIMEDIA source inside_zone destination multimedia_zone
service-policy type inspect IN_MULTIMEDIA

!
!
class-map type inspect match-any IN_PERIPHERAL
match protocol tcp
!
policy-map type inspect IN_PERIPHERAL
class type inspect IN_PERIPHERAL
inspect
class class-default
drop

!
zone-pair security IN->PERIPHERAL source inside_zone destination peripheral_zone
service-policy type inspect IN_PERIPHERAL

!
!
class-map type inspect match-any PERIPHERAL_IN
match protocol tcp
match access-group name PERIPHERAL_INSPECT

!
policy-map type inspect PERIPHERAL_IN
class type inspect PERIPHERAL_IN
inspect
class class-default
drop

!
zone-pair security PERIPHERAL->IN source peripheral_zone destination inside_zone
service-policy type inspect PERIPHERAL_IN

!
!
Interface fa0/1.3
Zone-member security inside_zone
!
Interface fa0/1.4
Zone-member security inside_zone
!
Interface vlan 2
Zone-member security multimedia_zone
!
Interface vlan 10
Zone-member security dmz_zone
!
Interface fa0/0
Zone-member security outside_zone

Troubleshooting :

show policy-map type inspect zone-pair sessions
clear zone-pair inspect session policy-map MULTIMEDIA_OUT