<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic two firewall with same security level in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/two-firewall-with-same-security-level/m-p/2448636#M268310</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my topology is&lt;/P&gt;&lt;P&gt;&amp;nbsp;ISP 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISP 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;Firewall 1&amp;nbsp;----------Firewall 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;___&amp;nbsp; L3 Switch ___|&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both firewalls are connected back to back with same security level (60). - DMZ interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both firewalls run ospf and default route is injected by firewall 1 to firewall 2 (dmz interface) and l3 switch - which is all fine. I can see the ospf routes but when i try to ping outside world from Firewall 2 through to Firewall 1 on dmz interface i cant seem to get a response although from L3 switch i can ping outside world ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried adding same-security level permit inter interface traffic (or something similar) on both interface of the firewall but no joy. any thoughts please ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:56:43 GMT</pubDate>
    <dc:creator>Network Pro</dc:creator>
    <dc:date>2019-03-12T03:56:43Z</dc:date>
    <item>
      <title>two firewall with same security level</title>
      <link>https://community.cisco.com/t5/network-security/two-firewall-with-same-security-level/m-p/2448636#M268310</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my topology is&lt;/P&gt;&lt;P&gt;&amp;nbsp;ISP 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISP 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;Firewall 1&amp;nbsp;----------Firewall 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;___&amp;nbsp; L3 Switch ___|&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both firewalls are connected back to back with same security level (60). - DMZ interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both firewalls run ospf and default route is injected by firewall 1 to firewall 2 (dmz interface) and l3 switch - which is all fine. I can see the ospf routes but when i try to ping outside world from Firewall 2 through to Firewall 1 on dmz interface i cant seem to get a response although from L3 switch i can ping outside world ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried adding same-security level permit inter interface traffic (or something similar) on both interface of the firewall but no joy. any thoughts please ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:56:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-firewall-with-same-security-level/m-p/2448636#M268310</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2019-03-12T03:56:43Z</dc:date>
    </item>
    <item>
      <title>I don't think it is a same</title>
      <link>https://community.cisco.com/t5/network-security/two-firewall-with-same-security-level/m-p/2448637#M268312</link>
      <description>&lt;P&gt;I don't think it is a same-security issue as these are separate firewalls.&lt;/P&gt;&lt;P&gt;Are the DMZ interfaces using private addressing and if so have you setup NAT for them when they go via the outside interface ?&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2014 12:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-firewall-with-same-security-level/m-p/2448637#M268312</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-14T12:07:57Z</dc:date>
    </item>
    <item>
      <title>As Jon has mentioned this is</title>
      <link>https://community.cisco.com/t5/network-security/two-firewall-with-same-security-level/m-p/2448638#M268317</link>
      <description>&lt;P&gt;As Jon has mentioned this is not a security level issue, and is most likely a NAT issue, or possible a routing issue though this is very unlikely.&lt;/P&gt;&lt;P&gt;Please post the running configue (remove all passwords and public IPs) for both the ASAs.&amp;nbsp; Seeing the configuration will help us identify where the problem might be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2014 12:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-firewall-with-same-security-level/m-p/2448638#M268317</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-03-14T12:54:45Z</dc:date>
    </item>
  </channel>
</rss>

