<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cannot block traffic in ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-block-traffic-in-asa/m-p/2702125#M194239</link>
    <description>&lt;P&gt;Hi all expert here.&amp;nbsp; I have some issue with deny traffic from low interface back.&amp;nbsp; I&amp;nbsp; have&amp;nbsp; server behind interface with sec level 0&amp;nbsp; and have access list that permit only&amp;nbsp; certain&amp;nbsp; traffic from that host via 8080 to another client host. any other traffic from this host to any was denied.&lt;/P&gt;&lt;P&gt;But all client from interface with high level security than this without access list have permit to this host to any ports for connections.&lt;/P&gt;&lt;P&gt;How can I resolve this issue without&amp;nbsp; implement access list in high level interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks all before&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:12:07 GMT</pubDate>
    <dc:creator>elnurh</dc:creator>
    <dc:date>2019-03-12T06:12:07Z</dc:date>
    <item>
      <title>cannot block traffic in ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-block-traffic-in-asa/m-p/2702125#M194239</link>
      <description>&lt;P&gt;Hi all expert here.&amp;nbsp; I have some issue with deny traffic from low interface back.&amp;nbsp; I&amp;nbsp; have&amp;nbsp; server behind interface with sec level 0&amp;nbsp; and have access list that permit only&amp;nbsp; certain&amp;nbsp; traffic from that host via 8080 to another client host. any other traffic from this host to any was denied.&lt;/P&gt;&lt;P&gt;But all client from interface with high level security than this without access list have permit to this host to any ports for connections.&lt;/P&gt;&lt;P&gt;How can I resolve this issue without&amp;nbsp; implement access list in high level interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks all before&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-block-traffic-in-asa/m-p/2702125#M194239</guid>
      <dc:creator>elnurh</dc:creator>
      <dc:date>2019-03-12T06:12:07Z</dc:date>
    </item>
    <item>
      <title>Hi,As per your requirement ,</title>
      <link>https://community.cisco.com/t5/network-security/cannot-block-traffic-in-asa/m-p/2702126#M194240</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;As per your requirement , if you want the traffic to be blocked from the hosts from Higher Security Level to Lower , you would have to use ACL as that would be the only option.&lt;/P&gt;&lt;P&gt;The only other option would be to reduce the Security level on the other interface.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2015 12:07:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-block-traffic-in-asa/m-p/2702126#M194240</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-07-01T12:07:30Z</dc:date>
    </item>
    <item>
      <title>I have acl that implemented</title>
      <link>https://community.cisco.com/t5/network-security/cannot-block-traffic-in-asa/m-p/2702127#M194241</link>
      <description>&lt;P&gt;I have acl that implemented on low level interface but this acl not working.&lt;/P&gt;&lt;P&gt;I want to understand why&amp;nbsp; without acl in high level interface I can't block return traffic via acl in low level interface ????????????????&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 09:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-block-traffic-in-asa/m-p/2702127#M194241</guid>
      <dc:creator>elnurh</dc:creator>
      <dc:date>2015-07-02T09:56:52Z</dc:date>
    </item>
    <item>
      <title>You can't block it because</title>
      <link>https://community.cisco.com/t5/network-security/cannot-block-traffic-in-asa/m-p/2702128#M194242</link>
      <description>&lt;P&gt;You can't block it because the ASA is a stateful firewall.&lt;/P&gt;&lt;P&gt;What this means is that if traffic is allowed in one direction then the return traffic is allowed without checking acls because there is an entry in the state table.&lt;/P&gt;&lt;P&gt;The acl in your example is only checked when the traffic is initiated from the server ie. there is no entry in the state table.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 16:19:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-block-traffic-in-asa/m-p/2702128#M194242</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-07-02T16:19:10Z</dc:date>
    </item>
  </channel>
</rss>

