<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Control Traffic Higher Security Level to Lower Security Level in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5123760#M1113311</link>
    <description>&lt;P&gt;I would suggest 7.2 Code is too old, there many things changed after that, so better upgrade latest to 9.16 (last released for that product) - when you upgrade many things are changed so your old configuration may not work as expected, so read the changes and make necessary changes as needed.&lt;/P&gt;
&lt;P&gt;you can have ACL only Allow IP and rest deny in the ACL is that not works for you ?&lt;/P&gt;
&lt;P&gt;other way you can only add required address to NAT, rest they will be not allowed. (may be bit of manual task that work)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jun 2024 19:10:38 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2024-06-03T19:10:38Z</dc:date>
    <item>
      <title>Control Traffic Higher Security Level to Lower Security Level</title>
      <link>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5123309#M1113281</link>
      <description>&lt;P&gt;Hi everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im use ASA 5506-X ver 7.2. I know all traffic can flow from Higher Security Level to Lower Security level but Is it possible to create a limit IP list can accessing outside and how I can configure this?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 10:32:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5123309#M1113281</guid>
      <dc:creator>anhnt621994</dc:creator>
      <dc:date>2024-06-03T10:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Control Traffic Higher Security Level to Lower Security Level</title>
      <link>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5123322#M1113286</link>
      <description>&lt;P&gt;if you try to tune access to asa interface itself Use control-plane ACL&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221457-configure-control-plane-access-control-p.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221457-configure-control-plane-access-control-p.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;if other please can you more elaborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 11:12:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5123322#M1113286</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-03T11:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Control Traffic Higher Security Level to Lower Security Level</title>
      <link>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5123760#M1113311</link>
      <description>&lt;P&gt;I would suggest 7.2 Code is too old, there many things changed after that, so better upgrade latest to 9.16 (last released for that product) - when you upgrade many things are changed so your old configuration may not work as expected, so read the changes and make necessary changes as needed.&lt;/P&gt;
&lt;P&gt;you can have ACL only Allow IP and rest deny in the ACL is that not works for you ?&lt;/P&gt;
&lt;P&gt;other way you can only add required address to NAT, rest they will be not allowed. (may be bit of manual task that work)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 19:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5123760#M1113311</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-06-03T19:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Control Traffic Higher Security Level to Lower Security Level</title>
      <link>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5126475#M1113380</link>
      <description>&lt;P&gt;Thank for your reply.&lt;/P&gt;&lt;P&gt;I tried to add ACL here (file attached) but I can't override the access of security level 100, any IP in this interface can reach other. Do I need to choose other level security for this interface and apply ACL?&lt;/P&gt;&lt;P&gt;Sorry my knowledge is not good so I dont know how to use control plan access control in my situation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;About the version, because the device place in OT network so we cant update usually.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 11:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5126475#M1113380</guid>
      <dc:creator>anhnt621994</dc:creator>
      <dc:date>2024-06-06T11:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Control Traffic Higher Security Level to Lower Security Level</title>
      <link>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5126530#M1113382</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ASA ACL.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/220211iFD1235D694E05E41/image-size/large?v=v2&amp;amp;px=999" role="button" title="ASA ACL.png" alt="ASA ACL.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 13:22:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/control-traffic-higher-security-level-to-lower-security-level/m-p/5126530#M1113382</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-06T13:22:12Z</dc:date>
    </item>
  </channel>
</rss>

