<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why would you want to modify in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/modification-in-interface-security-level-of-outside-interface-on/m-p/2489836#M268146</link>
    <description>&lt;P&gt;Why would you want to modify the outside security level? The value needs to be set as 0. This is because the default behaviour of ASA that won't allow traffic flowing from lower to higher security level unless permitted by ACLs. This way it will automatically protect your inside/dmz network from outside/internet.&lt;/P&gt;&lt;P&gt;By default when you configure nameif on all interfaces, they will have security level of 0 unless if you name it as "inside" then it will have security level of 100. You can modify the security level under interface level with&amp;nbsp;&lt;STRONG&gt;security-level&lt;/STRONG&gt;&amp;nbsp;command.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the impact, I don't know. I never tried it/measured it before. I assume it won't have any impact as long as the outside's security level is still lower than all other interfaces in your ASA after you modify it.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Mar 2014 10:07:07 GMT</pubDate>
    <dc:creator>Rudy Sanjoko</dc:creator>
    <dc:date>2014-03-21T10:07:07Z</dc:date>
    <item>
      <title>modification in interface security level of outside interface on running asa device</title>
      <link>https://community.cisco.com/t5/network-security/modification-in-interface-security-level-of-outside-interface-on/m-p/2489835#M268145</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please provide the information that &amp;nbsp;can i change the security level on my asa firewall for outside interface. This ASA firewall presently running and handling the live traffice.&lt;/P&gt;&lt;P&gt;Will it impact on the traffice if change the security level.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/modification-in-interface-security-level-of-outside-interface-on/m-p/2489835#M268145</guid>
      <dc:creator>navratan.nawariya</dc:creator>
      <dc:date>2019-03-26T00:53:11Z</dc:date>
    </item>
    <item>
      <title>Why would you want to modify</title>
      <link>https://community.cisco.com/t5/network-security/modification-in-interface-security-level-of-outside-interface-on/m-p/2489836#M268146</link>
      <description>&lt;P&gt;Why would you want to modify the outside security level? The value needs to be set as 0. This is because the default behaviour of ASA that won't allow traffic flowing from lower to higher security level unless permitted by ACLs. This way it will automatically protect your inside/dmz network from outside/internet.&lt;/P&gt;&lt;P&gt;By default when you configure nameif on all interfaces, they will have security level of 0 unless if you name it as "inside" then it will have security level of 100. You can modify the security level under interface level with&amp;nbsp;&lt;STRONG&gt;security-level&lt;/STRONG&gt;&amp;nbsp;command.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the impact, I don't know. I never tried it/measured it before. I assume it won't have any impact as long as the outside's security level is still lower than all other interfaces in your ASA after you modify it.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 10:07:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/modification-in-interface-security-level-of-outside-interface-on/m-p/2489836#M268146</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2014-03-21T10:07:07Z</dc:date>
    </item>
    <item>
      <title>Yes it is possible to change</title>
      <link>https://community.cisco.com/t5/network-security/modification-in-interface-security-level-of-outside-interface-on/m-p/2489837#M268147</link>
      <description>&lt;P&gt;Yes it is possible to change it while in production. You must keep it lower than all your other interfaces though.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 14:38:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/modification-in-interface-security-level-of-outside-interface-on/m-p/2489837#M268147</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2014-03-21T14:38:04Z</dc:date>
    </item>
  </channel>
</rss>

