<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is this a school problem?In in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661466#M194940</link>
    <description>&lt;P&gt;Is this a school problem?&lt;/P&gt;&lt;P&gt;In any case, the very simple problem you pose would not be best done with ACLs but rather with security-level setup.&lt;/P&gt;&lt;P&gt;Just make 1-4 all same security level. Make #5 lower security level (but not as low as outside). PErmit traffic inter-interface same secuirty level and voila it works as requested.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2015 13:31:55 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-04-17T13:31:55Z</dc:date>
    <item>
      <title>how to secure Inside traffice on Cisco ASA 5512-x</title>
      <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661461#M194935</link>
      <description>&lt;P&gt;folks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a ASA with 5 interfaces installed (1 for outside and 4 for inside), at the minute only outside interface has ACLs configured and all the inside interfaces dont have any rules on them at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been asked to configure some ACLs for the inside network so that only the servers connected to the inside interfaces can talk to each other. Please find the attached diagram&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question is how to create ACLs for servers that are directly connected to the ASA?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661461#M194935</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2019-03-12T05:47:21Z</dc:date>
    </item>
    <item>
      <title>Hi,As per your requirement ,</title>
      <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661462#M194936</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;As per your requirement , If you want the traffic between the servers which i am guessing would be the same Broadcast domain , you would not be able to block/Permit it using the ACL on the inside interface as that traffic would never be filtered on the ASA device.&lt;/P&gt;&lt;P&gt;You can block other traffic to other destination except for the one between the servers.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 11:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661462#M194936</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-04-17T11:46:42Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor Thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661463#M194937</link>
      <description>&lt;P&gt;Hi Vibhor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Those 4 servers are on different boradcast domains, they are connected&amp;nbsp;to the ASA via different Switches (sorry, forgot to incude the switches on the diagram)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 12:11:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661463#M194937</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2015-04-17T12:11:35Z</dc:date>
    </item>
    <item>
      <title>Hi,So , if i understand , in</title>
      <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661464#M194938</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;So , if i understand , in that case it has to be 4 Interface/Sub Interfaces on the ASA device acting as the gateway for four server ?&lt;/P&gt;&lt;P&gt;If the switches are Layer 2 still , the ACL would not work. It has to be different IP subnet.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 12:26:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661464#M194938</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-04-17T12:26:26Z</dc:date>
    </item>
    <item>
      <title>Hi VibhorAlmost correct,</title>
      <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661465#M194939</link>
      <description>&lt;P&gt;Hi Vibhor&lt;/P&gt;&lt;P&gt;Almost correct, Switches are still L2 but servers are on different subnets tho&lt;/P&gt;&lt;P&gt;To help me make it more clearer I have created a new diagram.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your time&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 12:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661465#M194939</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2015-04-17T12:54:24Z</dc:date>
    </item>
    <item>
      <title>Is this a school problem?In</title>
      <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661466#M194940</link>
      <description>&lt;P&gt;Is this a school problem?&lt;/P&gt;&lt;P&gt;In any case, the very simple problem you pose would not be best done with ACLs but rather with security-level setup.&lt;/P&gt;&lt;P&gt;Just make 1-4 all same security level. Make #5 lower security level (but not as low as outside). PErmit traffic inter-interface same secuirty level and voila it works as requested.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 13:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661466#M194940</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-04-17T13:31:55Z</dc:date>
    </item>
    <item>
      <title>Hi MarvinDont know why I cant</title>
      <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661467#M194941</link>
      <description>&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;Hi Marvin&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;Dont know why I cant see your reply on this thread.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;This is not a school problem, I am new(ish) to networking, is it necessary to have ACLs for the inside network? if it is then is it good practice to solely repy on security level to secure it?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;Cheers&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;Hi &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="https://supportforums.cisco.com/users/lionkin1984"&gt;&lt;U&gt;&lt;FONT color="#424282" face="Arial" size="3"&gt;&lt;FONT color="#424282" face="Arial" size="3"&gt;&lt;FONT color="#424282" face="Arial" size="3"&gt;LionKin1984&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;,&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;A href="https://supportforums.cisco.com/users/mrhoads-cco"&gt;&lt;U&gt;&lt;FONT color="#424282" face="Arial" size="3"&gt;&lt;FONT color="#424282" face="Arial" size="3"&gt;&lt;FONT color="#424282" face="Arial" size="3"&gt;Marvin Rhoads&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt; has commented on &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="https://supportforums.cisco.com/discussion/12480321/how-secure-inside-traffice-cisco-asa-5512-x"&gt;&lt;U&gt;&lt;FONT color="#424282" face="Arial" size="3"&gt;&lt;FONT color="#424282" face="Arial" size="3"&gt;&lt;FONT color="#424282" face="Arial" size="3"&gt;Discussion how to secure Inside traffice on Cisco ASA 5512-x&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;　&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;　&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;Is this a school problem?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;In any case, the very simple problem you pose would not be best done with ACLs but rather with security-level setup.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;Just make 1-4 all same security level. Make #5 lower security level (but not as low as outside). PErmit traffic inter-interface same secuirty level and voila it works as requested.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 13:42:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661467#M194941</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2015-04-17T13:42:30Z</dc:date>
    </item>
    <item>
      <title>LionKin,There was a CSC</title>
      <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661468#M194942</link>
      <description>&lt;P&gt;LionKin,&lt;/P&gt;&lt;P&gt;There was a CSC upgrade last night and I have been seeing some oddness as well this morning. In any case...&lt;/P&gt;&lt;P&gt;You have four subnets connected to four interfaces of the same security level, with a fifth one differentiated. You only have one server on each subnet and you want the first four&amp;nbsp;all to be able to talk to one another. Adding security policy doesn't accomplish much security-wise. In fact, putting the ASA in the path between them doesn't accomplish much. Having them all connect via a common L2/L3 switching (routing) infrastructure is generally better.&lt;/P&gt;&lt;P&gt;The question as you posed it is pretty abstract and doesn't seem very "real world". That's why I asked about a school tie-in.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 13:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661468#M194942</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-04-17T13:51:20Z</dc:date>
    </item>
    <item>
      <title>Thanks MarvinI assume you</title>
      <link>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661469#M194943</link>
      <description>&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;Thanks Marvin&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;I assume you have seen the diagram (the second one)I uploaded on this thread, I have to admit that our set up is not the best ..&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;The firewall does the routing and filtering all by itself, we have 5 interfaces on the firewall but only the 'Outside' interface has ACLs configured on it, the other 4 (inside network interfaces) dont.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;All inside interfaces have high security levels, I have suggested putting a L3 switch or a router between the servers on the inside network and ASA but due to funding issues it didnt fly,&amp;nbsp;instead they want me to put some ACLs on the inside interfaces ...&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;LionKin,&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;There was a CSC upgrade last night and I have been seeing some oddness as well this morning. In any case...&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;You have four subnets connected to four interfaces of the same security level, with a fifth one differentiated. You only have one server on each subnet and you want the first four all to be able to talk to one another. Adding security policy doesn't accomplish much security-wise. In fact, putting the ASA in the path between them doesn't accomplish much. Having them all connect via a common L2/L3 switching (routing) infrastructure is generally better.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;&lt;FONT color="#4f4f4f" face="Arial" size="3"&gt;The question as you posed it is pretty abstract and doesn't seem very "real world". That's why I asked about a school tie-in.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2015 14:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-secure-inside-traffice-on-cisco-asa-5512-x/m-p/2661469#M194943</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2015-04-17T14:04:27Z</dc:date>
    </item>
  </channel>
</rss>

