<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Security Level Help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-security-level-help/m-p/2749101#M178045</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've just started a new role and after looking at the ASA 5550 config I have an issue. &amp;nbsp;The inside interface has security level 0 and outside security level 100!&lt;/P&gt;&lt;P&gt;It's been like this for years!&lt;/P&gt;&lt;P&gt;So there're lots of inbound rules , some NAT entries and a couple of site-to-site VPN's attached to outside interface that has built up over the years so the config is working.&lt;/P&gt;&lt;P&gt;So what I'm asking is if I were to swap security levels to the way it should be, surly the exiting config shouldn't be affected by the change?&lt;/P&gt;&lt;P&gt;Cheers&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:43:53 GMT</pubDate>
    <dc:creator>joepeters1982</dc:creator>
    <dc:date>2019-03-12T06:43:53Z</dc:date>
    <item>
      <title>ASA Security Level Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-security-level-help/m-p/2749101#M178045</link>
      <description />
      <pubDate>Tue, 12 Mar 2019 06:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-security-level-help/m-p/2749101#M178045</guid>
      <dc:creator>joepeters1982</dc:creator>
      <dc:date>2019-03-12T06:43:53Z</dc:date>
    </item>
    <item>
      <title>Hi, If you are planning to</title>
      <link>https://community.cisco.com/t5/network-security/asa-security-level-help/m-p/2749102#M178047</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are planning to change the security levels of the interface then should consider the traffic that should be permitted from the new lower security level interface to higher security level interface.&lt;/P&gt;&lt;P&gt;Also you have mentioned that you already have ACLs on the inside interface. So once you change the security level to 100 on the inside interface, the ACL will still take precedence and you will need to add more ACL entries to permit/deny traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!!!&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:10px;"&gt;Don't forget to mark the answer as correct if it helps in resolving your query!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 09:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-security-level-help/m-p/2749102#M178047</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-12T09:23:31Z</dc:date>
    </item>
    <item>
      <title>Thanks RishabhAfter checking</title>
      <link>https://community.cisco.com/t5/network-security/asa-security-level-help/m-p/2749103#M178051</link>
      <description>&lt;P&gt;Thanks Rishabh&lt;/P&gt;&lt;P&gt;After checking and re-checking finally swapped security levels, all seems ok so far...PHEW&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 07:13:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-security-level-help/m-p/2749103#M178051</guid>
      <dc:creator>joepeters1982</dc:creator>
      <dc:date>2015-10-14T07:13:48Z</dc:date>
    </item>
    <item>
      <title>Great :)!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-security-level-help/m-p/2749104#M178054</link>
      <description>&lt;P&gt;Great :)!!!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 07:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-security-level-help/m-p/2749104#M178054</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-14T07:14:43Z</dc:date>
    </item>
  </channel>
</rss>

