<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: traffic allowed by default from higher to lower security zone in firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traffic-allowed-by-default-from-higher-to-lower-security-zone-in/m-p/3680303#M14188</link>
    <description>thank you very much</description>
    <pubDate>Thu, 02 Aug 2018 18:20:09 GMT</pubDate>
    <dc:creator>rocky2024</dc:creator>
    <dc:date>2018-08-02T18:20:09Z</dc:date>
    <item>
      <title>traffic allowed by default from higher to lower security zone in firewall</title>
      <link>https://community.cisco.com/t5/network-security/traffic-allowed-by-default-from-higher-to-lower-security-zone-in/m-p/3679923#M14125</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In ASA, all traffic allowed by default from higher to lower zone i.e. inside to outside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Do we need to allow return traffic on outside interface ? if yes then understanding will like this, traffic allowed by default from inside to outside but return traffic should be allowed on outside interface in inbound direction. correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Please clarify whether all type of traffic and all ports TCP/UDP allowed by default from inside to outside ? absolutely all traffic ??? or certain ports are not allowed by default from Inside to outside?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Sourabh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:02:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-allowed-by-default-from-higher-to-lower-security-zone-in/m-p/3679923#M14125</guid>
      <dc:creator>rocky2024</dc:creator>
      <dc:date>2020-02-21T16:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: traffic allowed by default from higher to lower security zone in firewall</title>
      <link>https://community.cisco.com/t5/network-security/traffic-allowed-by-default-from-higher-to-lower-security-zone-in/m-p/3679933#M14145</link>
      <description>Hi,&lt;BR /&gt;The ASA is stateful and keeps a track of all outbound tcp/udp connections, so when you make a connection outbound it will automatically permit the return traffic.&lt;BR /&gt;&lt;BR /&gt;An exception to this is icmp, it is not stateful like tcp/udp, so you either need to enable "inspect icmp" in the policy map or modify an ACL on the outside interface permitting the traffic.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Thu, 02 Aug 2018 11:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-allowed-by-default-from-higher-to-lower-security-zone-in/m-p/3679933#M14145</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-08-02T11:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: traffic allowed by default from higher to lower security zone in firewall</title>
      <link>https://community.cisco.com/t5/network-security/traffic-allowed-by-default-from-higher-to-lower-security-zone-in/m-p/3679989#M14170</link>
      <description>&lt;P&gt;in a nutshell, access lists are applied in an ingress direction, so, if you initiate, yes initiate ttraffic for instance on port 80 and hit your inside interface to go to cnn.com the the response from cnn does NOT have to be explicitly permitted.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 13:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-allowed-by-default-from-higher-to-lower-security-zone-in/m-p/3679989#M14170</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-08-02T13:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: traffic allowed by default from higher to lower security zone in firewall</title>
      <link>https://community.cisco.com/t5/network-security/traffic-allowed-by-default-from-higher-to-lower-security-zone-in/m-p/3680303#M14188</link>
      <description>thank you very much</description>
      <pubDate>Thu, 02 Aug 2018 18:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-allowed-by-default-from-higher-to-lower-security-zone-in/m-p/3680303#M14188</guid>
      <dc:creator>rocky2024</dc:creator>
      <dc:date>2018-08-02T18:20:09Z</dc:date>
    </item>
  </channel>
</rss>

