<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA security level concept question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-security-level-concept-question/m-p/2460643#M1003308</link>
    <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;Need some help regarding ACL configuration.&lt;/P&gt;&lt;P&gt;Let's say I have an ASA with 4 interfaces (A, B, C and outside. Security levels for A,B,C are equal, outside is less)&lt;/P&gt;&lt;P&gt;All clients on networks A,B,C are allowed to connect to outside. In this case I don't need to configure an ACL as all traffic to less secure networks is allowed.&lt;/P&gt;&lt;P&gt;But what to do if I want to allow one host on interface A to connect to one host on interface B? Of course, I can add an ACE to interface' A inside ACL to allow that but will loose my implicit rule and connectivity to outside.&lt;/P&gt;&lt;P&gt;Is there a way to add an ACE on inside ACL for interface A allowing traffic that needs to go out of outside?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 13:11:53 GMT</pubDate>
    <dc:creator>ICFCISCO1</dc:creator>
    <dc:date>2020-02-21T13:11:53Z</dc:date>
    <item>
      <title>ASA security level concept question</title>
      <link>https://community.cisco.com/t5/network-security/asa-security-level-concept-question/m-p/2460643#M1003308</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;Need some help regarding ACL configuration.&lt;/P&gt;&lt;P&gt;Let's say I have an ASA with 4 interfaces (A, B, C and outside. Security levels for A,B,C are equal, outside is less)&lt;/P&gt;&lt;P&gt;All clients on networks A,B,C are allowed to connect to outside. In this case I don't need to configure an ACL as all traffic to less secure networks is allowed.&lt;/P&gt;&lt;P&gt;But what to do if I want to allow one host on interface A to connect to one host on interface B? Of course, I can add an ACE to interface' A inside ACL to allow that but will loose my implicit rule and connectivity to outside.&lt;/P&gt;&lt;P&gt;Is there a way to add an ACE on inside ACL for interface A allowing traffic that needs to go out of outside?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-security-level-concept-question/m-p/2460643#M1003308</guid>
      <dc:creator>ICFCISCO1</dc:creator>
      <dc:date>2020-02-21T13:11:53Z</dc:date>
    </item>
    <item>
      <title>There is a command for this: </title>
      <link>https://community.cisco.com/t5/network-security/asa-security-level-concept-question/m-p/2460644#M1003316</link>
      <description>&lt;P&gt;There is a command for this:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa81/command/ref/refgd/s1.html#wp1383263"&gt;same-security-traffic permit inter-interface&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you only want to allow to a single host on the other same security interface then you need to be more creative with multiple ACEs in your access-list:&lt;/P&gt;&lt;P&gt;permit host to host&lt;/P&gt;&lt;P&gt;deny to the other subnets on the same security interfaces&lt;/P&gt;&lt;P&gt;permit to all others&lt;/P&gt;</description>
      <pubDate>Sat, 24 May 2014 14:58:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-security-level-concept-question/m-p/2460644#M1003316</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-24T14:58:49Z</dc:date>
    </item>
  </channel>
</rss>

