<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA implicit deny rule in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-implicit-deny-rule/m-p/2469740#M268248</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a 5550 working in routed mode with 8.0(4) version. My configuration have one physical interface&amp;nbsp;in tunnel mode with 4 subinterface,&amp;nbsp;3 of them are inside and the forth one is dmz interface.&amp;nbsp;Another phisical interface is configured as Outside interface.&lt;/P&gt;&lt;P&gt;On the inside interfaces there are applied ACLs inbound to allow only permitted traffic and at the end of all ACL there are the implicit deny rule. As I excpected all and just all permitted traffic by acl are allowed to pass through inside interfaces to less secure interface as Outside, while all other traffic denied by implicit deny rule. Instead I am experiencing a strange behavior on the inside interfaces that i can't undestand, It seems as implicit deny rule not working and all traffic is permitted. To block traffic I needed to apply manually a deny any any rule to all inside interface's ACL.&lt;/P&gt;&lt;P&gt;Can pleas anyone help me to undestand this behaviour? Is it due a wrong configuration or just a bug?&lt;/P&gt;&lt;P&gt;Any suggestion&amp;nbsp;will be&amp;nbsp;very appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;angelo&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:57:33 GMT</pubDate>
    <dc:creator>ANGELO DE MASI</dc:creator>
    <dc:date>2019-03-12T03:57:33Z</dc:date>
    <item>
      <title>ASA implicit deny rule</title>
      <link>https://community.cisco.com/t5/network-security/asa-implicit-deny-rule/m-p/2469740#M268248</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a 5550 working in routed mode with 8.0(4) version. My configuration have one physical interface&amp;nbsp;in tunnel mode with 4 subinterface,&amp;nbsp;3 of them are inside and the forth one is dmz interface.&amp;nbsp;Another phisical interface is configured as Outside interface.&lt;/P&gt;&lt;P&gt;On the inside interfaces there are applied ACLs inbound to allow only permitted traffic and at the end of all ACL there are the implicit deny rule. As I excpected all and just all permitted traffic by acl are allowed to pass through inside interfaces to less secure interface as Outside, while all other traffic denied by implicit deny rule. Instead I am experiencing a strange behavior on the inside interfaces that i can't undestand, It seems as implicit deny rule not working and all traffic is permitted. To block traffic I needed to apply manually a deny any any rule to all inside interface's ACL.&lt;/P&gt;&lt;P&gt;Can pleas anyone help me to undestand this behaviour? Is it due a wrong configuration or just a bug?&lt;/P&gt;&lt;P&gt;Any suggestion&amp;nbsp;will be&amp;nbsp;very appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;angelo&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-implicit-deny-rule/m-p/2469740#M268248</guid>
      <dc:creator>ANGELO DE MASI</dc:creator>
      <dc:date>2019-03-12T03:57:33Z</dc:date>
    </item>
    <item>
      <title>Please post yoour config. All</title>
      <link>https://community.cisco.com/t5/network-security/asa-implicit-deny-rule/m-p/2469741#M268250</link>
      <description>&lt;P&gt;Please post yoour config. All in all it should work as expected.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2014 16:38:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-implicit-deny-rule/m-p/2469741#M268250</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-03-18T16:38:39Z</dc:date>
    </item>
    <item>
      <title>Hi Karsten,thank you for your</title>
      <link>https://community.cisco.com/t5/network-security/asa-implicit-deny-rule/m-p/2469742#M268251</link>
      <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;&lt;P&gt;thank you for your reply.&lt;/P&gt;&lt;P&gt;Issue is due the Cisco Bug ID CSCsq91277 . I solved to upgrade release on ASA.&lt;/P&gt;&lt;P&gt;Thank you anyway&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;angelo&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2014 15:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-implicit-deny-rule/m-p/2469742#M268251</guid>
      <dc:creator>ANGELO DE MASI</dc:creator>
      <dc:date>2014-03-19T15:24:59Z</dc:date>
    </item>
  </channel>
</rss>

