<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic  Hi Marvin,i was trying to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-traffic-flow-from-high-security-to-low-security-interface/m-p/2432245#M238744</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;i was trying to find answer for this and it was puzzling me&amp;nbsp; and you replied back.Learn something very important from you today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 04 May 2014 23:47:44 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2014-05-04T23:47:44Z</dc:date>
    <item>
      <title>ASA traffic flow from high security to low security interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-traffic-flow-from-high-security-to-low-security-interface/m-p/2432243#M238741</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA --&amp;nbsp; By default traffic is allowed from high to low security interface.&lt;/P&gt;&lt;P&gt;From&amp;nbsp; ASA i am telneting from inside interface which has security level 100 to other interface sales which has security level 50.&lt;/P&gt;&lt;P&gt;Deny tcp src inside:10.0.0.2/48646 dst sales:10.12.12.2/23 by access-group "inside_access_in" [0xbe9efe96, 0x0]&lt;/P&gt;&lt;P&gt;This only works if i put rule to allow telnet from inside to sales.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to know why traffic flow does not work without ACL even this is flowing from high to low security level.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:09:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traffic-flow-from-high-security-to-low-security-interface/m-p/2432243#M238741</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T04:09:26Z</dc:date>
    </item>
    <item>
      <title>Mahesh,You are correct about</title>
      <link>https://community.cisco.com/t5/network-security/asa-traffic-flow-from-high-security-to-low-security-interface/m-p/2432244#M238743</link>
      <description>&lt;P&gt;Mahesh,&lt;/P&gt;&lt;P&gt;You are correct about the default behavior. BUT there is one very important thing to remember. As soon as you have &lt;STRONG&gt;any&lt;/STRONG&gt; access list applied to the high security interface the default behavior is no longer in effect. Instead you will permit only the traffic that is explicitly defined in the access list.&lt;/P&gt;&lt;P&gt;All access lists have an implicit "deny any any" at the end. That's what is blocking your traffic as shown in your log message.&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2014 23:34:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traffic-flow-from-high-security-to-low-security-interface/m-p/2432244#M238743</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-04T23:34:31Z</dc:date>
    </item>
    <item>
      <title> Hi Marvin,i was trying to</title>
      <link>https://community.cisco.com/t5/network-security/asa-traffic-flow-from-high-security-to-low-security-interface/m-p/2432245#M238744</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;i was trying to find answer for this and it was puzzling me&amp;nbsp; and you replied back.Learn something very important from you today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2014 23:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traffic-flow-from-high-security-to-low-security-interface/m-p/2432245#M238744</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2014-05-04T23:47:44Z</dc:date>
    </item>
  </channel>
</rss>

