<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic hi Neno, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914589#M154409</link>
    <description>&lt;P&gt;hi Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for the information.&lt;/P&gt;
&lt;P&gt;also I tested it in production environment and seems my traffic is dropped by implicit deny.&lt;/P&gt;
&lt;P&gt;and I wanted to ask if you encountered with something like this - I increased security level from &lt;SPAN style="text-decoration: line-through;"&gt;100&lt;/SPAN&gt; 0 to 50 (I had both &lt;SPAN style="text-decoration: line-through;"&gt;100&lt;/SPAN&gt; 0) and &lt;STRONG&gt;still&lt;/STRONG&gt;&amp;nbsp;need to have &lt;EM&gt;permit&lt;/EM&gt; statement to allow traffic flows from interface with security level 50 to interface with security level &lt;SPAN style="text-decoration: line-through;"&gt;100&lt;/SPAN&gt; 0.&lt;/P&gt;
&lt;P&gt;is it expected behaviour?&lt;/P&gt;</description>
    <pubDate>Mon, 02 May 2016 07:14:52 GMT</pubDate>
    <dc:creator>Ruslan Moldaliev</dc:creator>
    <dc:date>2016-05-02T07:14:52Z</dc:date>
    <item>
      <title>ASA - same-security-traffic permit inter-interface VS access-list permit/deny</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914585#M154405</link>
      <description>&lt;P&gt;hi folks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm wondering if I use&amp;nbsp;&lt;EM&gt;same-security-traffic permit inter-interface&lt;/EM&gt; command at ASA and I have 2 separate interfaces with the same security level and ACL with a couple of explicit &lt;EM&gt;permit&lt;/EM&gt; rules, whether traffic not covered by those &lt;EM&gt;permit&lt;/EM&gt; statements will be blocked by implicit deny in the end of ACL or am I completely wrong in my thinking?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:40:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914585#M154405</guid>
      <dc:creator>Ruslan Moldaliev</dc:creator>
      <dc:date>2019-03-12T07:40:30Z</dc:date>
    </item>
    <item>
      <title>Hello Ruslan-</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914586#M154406</link>
      <description>&lt;P&gt;Hello Ruslan-&lt;/P&gt;
&lt;P&gt;Check out the link below &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Note&lt;/B&gt;&lt;IMG width="9" height="2" border="0" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" /&gt;&lt;SPAN&gt; All traffic allowed by the&lt;/SPAN&gt;&lt;B class="cBold"&gt; same-security-traffic intra-interface&lt;/B&gt;&lt;SPAN&gt; command is still subject to firewall rules. Be careful not to create an asymmetric routing situation that can cause return traffic not to traverse the ASA.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s1.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s1.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 19:00:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914586#M154406</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-27T19:00:53Z</dc:date>
    </item>
    <item>
      <title>hi Neno,</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914587#M154407</link>
      <description>&lt;P&gt;hi Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks, I saw this link, however it still doesn't answer my question.&lt;/P&gt;
&lt;P&gt;and wonder what will be with the traffic in the case described by me, whether it will drop or no, this is the question.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 19:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914587#M154407</guid>
      <dc:creator>Ruslan Moldaliev</dc:creator>
      <dc:date>2016-04-27T19:45:33Z</dc:date>
    </item>
    <item>
      <title>Yes, the ACL rule(s) would be</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914588#M154408</link>
      <description>&lt;P&gt;Yes, the ACL rule(s) would be examined and if traffic that is not permitted will be dropped.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 20:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914588#M154408</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-27T20:04:01Z</dc:date>
    </item>
    <item>
      <title>hi Neno,</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914589#M154409</link>
      <description>&lt;P&gt;hi Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for the information.&lt;/P&gt;
&lt;P&gt;also I tested it in production environment and seems my traffic is dropped by implicit deny.&lt;/P&gt;
&lt;P&gt;and I wanted to ask if you encountered with something like this - I increased security level from &lt;SPAN style="text-decoration: line-through;"&gt;100&lt;/SPAN&gt; 0 to 50 (I had both &lt;SPAN style="text-decoration: line-through;"&gt;100&lt;/SPAN&gt; 0) and &lt;STRONG&gt;still&lt;/STRONG&gt;&amp;nbsp;need to have &lt;EM&gt;permit&lt;/EM&gt; statement to allow traffic flows from interface with security level 50 to interface with security level &lt;SPAN style="text-decoration: line-through;"&gt;100&lt;/SPAN&gt; 0.&lt;/P&gt;
&lt;P&gt;is it expected behaviour?&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 07:14:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914589#M154409</guid>
      <dc:creator>Ruslan Moldaliev</dc:creator>
      <dc:date>2016-05-02T07:14:52Z</dc:date>
    </item>
    <item>
      <title>Yes, you must explicitly</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914590#M154410</link>
      <description>&lt;P&gt;Yes, you must explicitly permit traffic from a lower security level to a higher security level interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 07:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914590#M154410</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-05-02T07:14:53Z</dc:date>
    </item>
    <item>
      <title>Neno,</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914591#M154411</link>
      <description>&lt;P&gt;Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for the explanation, but I admitted mistake in my previous post. please pay attention to strikethrough text.&lt;/P&gt;
&lt;P&gt;what would you say about that case?&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 20:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914591#M154411</guid>
      <dc:creator>Ruslan Moldaliev</dc:creator>
      <dc:date>2016-05-04T20:51:22Z</dc:date>
    </item>
    <item>
      <title>The only time when security</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914592#M154412</link>
      <description>&lt;P&gt;The only time when security-levels come into play is when you do not have an ACL configured on the interface. &amp;nbsp;If an ACL is configured then it is the ACL that counts with the implicit deny at the end of the ACL. &amp;nbsp;If there is no ACL on the interface then it is the security-level that comes into play.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2016 10:10:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914592#M154412</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2016-05-05T10:10:24Z</dc:date>
    </item>
    <item>
      <title>Marius,</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914593#M154413</link>
      <description>&lt;P&gt;Marius,&lt;/P&gt;
&lt;P&gt;do i understand you correctly that if I have ACL applied to the interfaces there is no matter what security-level is configured/present?&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2016 10:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914593#M154413</guid>
      <dc:creator>Ruslan Moldaliev</dc:creator>
      <dc:date>2016-05-05T10:34:41Z</dc:date>
    </item>
    <item>
      <title>That is correct.</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914594#M154414</link>
      <description>&lt;P&gt;That is correct.&lt;/P&gt;
&lt;P&gt;But then if you have an interface with an ACL and another interface without an ACL and you want to pass traffic between the two interfaces, then the interface without an ACL will rely on the security level while the interface with the ACL configured will rely on the ACL entries configured.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2016 11:13:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914594#M154414</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2016-05-05T11:13:45Z</dc:date>
    </item>
    <item>
      <title>Ahh ok, that makes sense :)</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914595#M154415</link>
      <description>&lt;P&gt;Ahh ok, that makes sense &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Yes, that is also expected behavior. The security-level interface becomes irrelevant if an ACL is applied to filter traffic on that particular interface. Thus, traffic flow that is not permitted in the ACL will be dropped due to the "implicit deny" at the end of the ACL. Here is a link to another good thread that explains this very well:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/discussion/11539041/asa-firewall-interface-security-levels-and-access-lists"&gt;https://supportforums.cisco.com/discussion/11539041/asa-firewall-interface-security-levels-and-access-lists&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2016 15:19:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/2914595#M154415</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-05-05T15:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: That is correct.</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/3190351#M154416</link>
      <description>&lt;P&gt;Hi..I have 2 interfaces DMZ1 and DMZ2 at the same security level. Traffic between the interfaces is allowed using:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DMZ1 has no ACLs as it is a new VLAN created. DMZ2 has lot of ACLs. According to you, DMZ1 should look at security level first as there are no ACLs. Then, DMZ1 would see that it has same security level as DMZ2 and allow traffic by the virtue of above commands. But this is not happening. When I run a packet tracer, it is denied by implicit deny rule. So, the idea of of the above commands doesn't seem make sense at all. Please help me clear my confusion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 14:08:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/3190351#M154416</guid>
      <dc:creator>sainathp</dc:creator>
      <dc:date>2017-09-27T14:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Ahh ok, that makes sense :)</title>
      <link>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/3329543#M154417</link>
      <description>&lt;P&gt;what if you have the ACL in place and not the inter-interface command.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;would that cause traffic not to be allowed&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2018 18:34:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-same-security-traffic-permit-inter-interface-vs-access-list/m-p/3329543#M154417</guid>
      <dc:creator>JRDIAZ758</dc:creator>
      <dc:date>2018-02-12T18:34:48Z</dc:date>
    </item>
  </channel>
</rss>

