<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why unable to access low security level interface? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918651#M24705</link>
    <description>&lt;P&gt;packet tracer&lt;/P&gt;&lt;P&gt;from 192.168.10.26, in inside network&amp;nbsp;&lt;/P&gt;&lt;P&gt;to 192.168.0.181,in test network,why destination is outside?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 747px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/44288i9137DDFECA674C92/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 936px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/44289i84FD8318BBD29F13/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Sep 2019 06:45:35 GMT</pubDate>
    <dc:creator>weichenyang06928</dc:creator>
    <dc:date>2019-09-04T06:45:35Z</dc:date>
    <item>
      <title>why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3917981#M24697</link>
      <description>&lt;P&gt;asa firewall, inside interface,security level 100, test interface,security level 40.&lt;/P&gt;&lt;P&gt;there is no access list on test interface.&lt;/P&gt;&lt;P&gt;depend on default rule, level 100 can access level 40.&amp;nbsp;&lt;/P&gt;&lt;P&gt;why unable to access?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 07:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3917981#M24697</guid>
      <dc:creator>weichenyang06928</dc:creator>
      <dc:date>2019-09-03T07:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3917991#M24698</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Since your didn't specify, does the inside interface have an inbound ACL configured on it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 08:08:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3917991#M24698</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2019-09-03T08:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918015#M24699</link>
      <description>&lt;P&gt;inside level 100:192.168.10.0,dmz level 50:192.168.100.0, test level 40:192.168.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there is acl:&lt;/P&gt;&lt;P&gt;access-list split extended permit ip 192.168.10.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list split extended permit ip 192.168.100.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list split extended permit ip 192.168.0.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;is this inbound acl?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but,no apply to inside interface(no access-group)&lt;/P&gt;&lt;P&gt;there is dmz, security level 50, inside can access dmz,but unable access security level 40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 08:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918015#M24699</guid>
      <dc:creator>weichenyang06928</dc:creator>
      <dc:date>2019-09-03T08:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918034#M24700</link>
      <description>&lt;P&gt;An ACL with the name 'split' sounds like it will be used for remote access VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you confirm if devices connected to the test interface are receiving packets from he inside interface? Do the devices on the test subnet have the correct subnet mask and gateway address?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 09:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918034#M24700</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2019-09-03T09:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918037#M24701</link>
      <description>&lt;P&gt;&lt;BR /&gt;ip local pool vpnpool 10.10.10.1-10.10.10.254&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;nameif Outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address x.x.x.x 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;nameif Inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.10.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;nameif DMZ&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 192.168.100.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;nameif Test&lt;BR /&gt;security-level 40&lt;BR /&gt;ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network pool&lt;BR /&gt;subnet 192.168.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network 192.168.0.11-9802&lt;BR /&gt;host 192.168.0.11&lt;BR /&gt;object network 192.168.0.11-9803&lt;BR /&gt;host 192.168.0.11&lt;BR /&gt;object network 192.168.0.11-9804&lt;BR /&gt;host 192.168.0.11&lt;BR /&gt;object network 192.168.100.88-8999&lt;BR /&gt;host 192.168.100.88&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list Outside-in extended permit tcp any host 192.168.0.11 eq 9802&lt;BR /&gt;access-list Outside-in extended permit tcp any host 192.168.0.11 eq 9803&lt;BR /&gt;access-list Outside-in extended permit tcp any host 192.168.0.11 eq 9804&lt;BR /&gt;access-list Outside-in extended permit tcp any host 192.168.100.88 eq 8999&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network 192.168.0.11-9802&lt;BR /&gt;nat (Test,Outside) static interface service tcp 9802 9802&lt;BR /&gt;object network 192.168.0.11-9803&lt;BR /&gt;nat (Test,Outside) static interface service tcp 9803 9803&lt;BR /&gt;object network 192.168.0.11-9804&lt;BR /&gt;nat (Test,Outside) static interface service tcp 9804 9804&lt;BR /&gt;object network 192.168.100.88-8999&lt;BR /&gt;nat (DMZ,Outside) static interface service tcp 8999 8999&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (Inside,Outside) after-auto source dynamic any interface&lt;BR /&gt;nat (Test,Outside) after-auto source dynamic any interface&lt;BR /&gt;access-group Outside-in in interface Outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 09:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918037#M24701</guid>
      <dc:creator>weichenyang06928</dc:creator>
      <dc:date>2019-09-03T09:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918043#M24702</link>
      <description>&lt;P&gt;Based on what you write (and don't write; you never say what exactly does not work) I assume that you are just doing a wrong test. Are you trying to access the IP of the ASA-interface Test from inside? That will not work by design on the ASA. Use real traffic (like something based on TCP) to a host on the test interface.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 09:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918043#M24702</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2019-09-03T09:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918083#M24703</link>
      <description>&lt;P&gt;You can always run the Packet Tracer to see what is blocking traffic. Packet Tracer is available in ASDM and you can also run it from CLI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can search for Packet Tracer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bhaggu&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 11:02:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918083#M24703</guid>
      <dc:creator>bhargavdesai</dc:creator>
      <dc:date>2019-09-03T11:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918651#M24705</link>
      <description>&lt;P&gt;packet tracer&lt;/P&gt;&lt;P&gt;from 192.168.10.26, in inside network&amp;nbsp;&lt;/P&gt;&lt;P&gt;to 192.168.0.181,in test network,why destination is outside?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 747px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/44288i9137DDFECA674C92/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 936px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/44289i84FD8318BBD29F13/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 06:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3918651#M24705</guid>
      <dc:creator>weichenyang06928</dc:creator>
      <dc:date>2019-09-04T06:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919390#M24707</link>
      <description>&lt;P&gt;It seems that your Gig 0/3 (TEST) is not up or having some issue. Can your post the output of&amp;nbsp;&lt;/P&gt;&lt;P&gt;Show route&amp;nbsp;&lt;/P&gt;&lt;P&gt;Show int ip brief&lt;/P&gt;&lt;P&gt;Show nameif&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for delayed response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bhaggu&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 06:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919390#M24707</guid>
      <dc:creator>bhargavdesai</dc:creator>
      <dc:date>2019-09-05T06:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919403#M24708</link>
      <description>&lt;P&gt;bhargavdesaith,thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test interface is up, public ip can access host which in test network.(port forward).&lt;/P&gt;&lt;P&gt;please see attach file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 07:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919403#M24708</guid>
      <dc:creator>weichenyang06928</dc:creator>
      <dc:date>2019-09-05T07:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919492#M24709</link>
      <description>&lt;P&gt;Can you post packet tracer log from SSH session. Moreover is there any Firepower PBR or other thing is picture.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;packet-tracer input Inside tcp 192.168.10.26 12345 192.168.0.181 9804 detailed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to know that is causing the destination to be on OUTSIDE rather than more specific TEST interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bhaggu.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 09:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919492#M24709</guid>
      <dc:creator>bhargavdesai</dc:creator>
      <dc:date>2019-09-05T09:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919504#M24710</link>
      <description>&lt;P&gt;object network vpndest1&lt;BR /&gt;subnet 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;there is definition in asa&lt;/P&gt;&lt;P&gt;nat (DMZ,Outside) source static vpnsource vpnsource destination static vpndest1&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 09:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919504#M24710</guid>
      <dc:creator>weichenyang06928</dc:creator>
      <dc:date>2019-09-05T09:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919514#M24712</link>
      <description>&lt;P&gt;According to the output the below rule may be causing issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (Inside,Outside) source static vpnsource1 vpnsource1 destination static vpndest1 vpndest1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you just share full configuration or try disabling the above NAT rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bhaggu&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 09:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919514#M24712</guid>
      <dc:creator>bhargavdesai</dc:creator>
      <dc:date>2019-09-05T09:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919952#M24717</link>
      <description>&lt;P&gt;bhargavdesai,&lt;/P&gt;&lt;P&gt;thanks for you help!&lt;/P&gt;&lt;P&gt;i disable nat rule&lt;/P&gt;&lt;P&gt;nat (Inside,Outside) source static vpnsource1 vpnsource1 destination static vpndest1 vpndest1&lt;/P&gt;&lt;P&gt;everything is fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2019 01:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919952#M24717</guid>
      <dc:creator>weichenyang06928</dc:creator>
      <dc:date>2019-09-06T01:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: why unable to access low security level interface?</title>
      <link>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919964#M24718</link>
      <description>Great that the solution worked for you.&lt;BR /&gt;I would request you to give proper credit by selecting response as answered and helpful so that it motivate and encourage to contribute to community.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bhaggu</description>
      <pubDate>Fri, 06 Sep 2019 03:12:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-unable-to-access-low-security-level-interface/m-p/3919964#M24718</guid>
      <dc:creator>bhargavdesai</dc:creator>
      <dc:date>2019-09-06T03:12:47Z</dc:date>
    </item>
  </channel>
</rss>

