<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 9.1 code enable traffic between interfaces with same sec in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/3811395#M347681</link>
    <description>It can be applied globally only.&lt;BR /&gt;</description>
    <pubDate>Thu, 28 Feb 2019 03:21:26 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2019-02-28T03:21:26Z</dc:date>
    <item>
      <title>ASA 9.1 code enable traffic between interfaces with same security levels</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263662#M347674</link>
      <description>&lt;P&gt;Asa 5525x with 9.1 code with multicontext&lt;BR /&gt;Mode enabled&lt;BR /&gt;&lt;BR /&gt;I enabled traffic between interfaces with same security level on admin firewall context . This works but when I disable this feature and apply inbound ACLs to these same interfaces log indicates packets are being denied by implicit policy even though my acl permits this traffic&lt;BR /&gt;Any clues to why this occurs ? Tried rebooting Asa after disabling same interface security level traffic to no avail.&lt;BR /&gt;&lt;BR /&gt;Thanks Team&lt;BR /&gt;&lt;BR /&gt;Scott&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263662#M347674</guid>
      <dc:creator>Scott Robertson</dc:creator>
      <dc:date>2019-03-12T02:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 code enable traffic between interfaces with same sec</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263663#M347675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have interfaces configured with same &lt;STRONG&gt;"security-level"&lt;/STRONG&gt; value then the only way traffic can pass between them is if you have &lt;STRONG&gt;"same-security-traffic permit inter-interface"&lt;/STRONG&gt; configuration enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So even if you allow traffic with &lt;STRONG&gt;"access-list"&lt;/STRONG&gt; configurations on the interfaces BUT you dont have the above configuration command enabled then traffic will still get blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you either have to configure &lt;STRONG&gt;"same-security-traffic permit inter-interface"&lt;/STRONG&gt; OR you will have to change either interfaces &lt;STRONG&gt;"security-level"&lt;/STRONG&gt; so they dont match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 15:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263663#M347675</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-20T15:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 code enable traffic between interfaces with same sec</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263664#M347676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So can/will Acl's control traffic on these interfaces with the same security level feature enabled and interfaces configured at same level or will all traffic be permitted regardless of ACL's if security levels are equal?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 16:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263664#M347676</guid>
      <dc:creator>Scott Robertson</dc:creator>
      <dc:date>2013-06-20T16:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 code enable traffic between interfaces with same sec</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263665#M347677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have &lt;STRONG&gt;"same-security-traffic permit inter-interface"&lt;/STRONG&gt; configured and have 2 interfaces with same &lt;STRONG&gt;"security-level"&lt;/STRONG&gt; value and you have &lt;STRONG&gt;"access-list"&lt;/STRONG&gt; configured on both interfaces then the ACLs will handle the decision of what traffic is allowed and what is not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the above case you could consider the &lt;STRONG&gt;"same-security-traffic permit inter-interface"&lt;/STRONG&gt; a kind of command that overcomes a default limitation of communication between interfaces with same &lt;STRONG&gt;"security-level"&lt;/STRONG&gt; interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically when you have interface ACLs configured then they will decide which traffic is allowed even if you have the &lt;STRONG&gt;"same-security-traffic"&lt;/STRONG&gt; configurations enabled&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do remember to mark the reply as the correct answer if it answered your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or ask more if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 16:21:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263665#M347677</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-20T16:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 code enable traffic between interfaces with same sec</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263666#M347678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you Jouni !&lt;/P&gt;&lt;P&gt;I understand the logic at this point and appreciate your qucik responses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 13:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/2263666#M347678</guid>
      <dc:creator>Scott Robertson</dc:creator>
      <dc:date>2013-06-21T13:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 code enable traffic between interfaces with same sec</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/3811383#M347679</link>
      <description />
      <pubDate>Thu, 28 Feb 2019 02:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/3811383#M347679</guid>
      <dc:creator>Ni2</dc:creator>
      <dc:date>2019-02-28T02:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 code enable traffic between interfaces with same sec</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/3811384#M347680</link>
      <description />
      <pubDate>Thu, 28 Feb 2019 02:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/3811384#M347680</guid>
      <dc:creator>drlbaluyut</dc:creator>
      <dc:date>2019-02-28T02:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 code enable traffic between interfaces with same sec</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/3811395#M347681</link>
      <description>It can be applied globally only.&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Feb 2019 03:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-code-enable-traffic-between-interfaces-with-same/m-p/3811395#M347681</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-02-28T03:21:26Z</dc:date>
    </item>
  </channel>
</rss>

