<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA recommended security levels in a data center in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501821#M417420</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm designing a network where&amp;nbsp; have 5580 ASAs in a Data center that will act as gateways for all business units in my DC.&lt;/P&gt;&lt;P&gt;I need to know what are the recommended security levels ( Database Servers, Users, Application servers) to benefit from all inspection and stateful ASA features knowing I won't use NATing in my enviroment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:02:08 GMT</pubDate>
    <dc:creator>k.abillama</dc:creator>
    <dc:date>2020-02-21T12:02:08Z</dc:date>
    <item>
      <title>ASA recommended security levels in a data center</title>
      <link>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501821#M417420</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm designing a network where&amp;nbsp; have 5580 ASAs in a Data center that will act as gateways for all business units in my DC.&lt;/P&gt;&lt;P&gt;I need to know what are the recommended security levels ( Database Servers, Users, Application servers) to benefit from all inspection and stateful ASA features knowing I won't use NATing in my enviroment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501821#M417420</guid>
      <dc:creator>k.abillama</dc:creator>
      <dc:date>2020-02-21T12:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA recommended security levels in a data center</title>
      <link>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501822#M417421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Security levels are used to define how secure the zone is considered. The less secure a zone is the lower the security level. And by definition you cannot flow from low to higher security levels without allowing it explicitly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I would put users in a lower security level, and then server on higher levels. I would set DB and App zone levels based on if you want DB servers to talk to App servers by default or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Jul 2010 00:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501822#M417421</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-07-24T00:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA recommended security levels in a data center</title>
      <link>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501823#M417422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's what I thought first but then I thought of putting users in higher security levels since they'll always be initiatng the connection( this way i'd take advantage of dynamic ports being opened for return traffic from higher to lower security zones, no?) will I lose in tems of inspection engine?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Jul 2010 06:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501823#M417422</guid>
      <dc:creator>k.abillama</dc:creator>
      <dc:date>2010-07-24T06:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA recommended security levels in a data center</title>
      <link>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501824#M417423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, inspections will still inspect statefully.&lt;/P&gt;&lt;P&gt;You can also apply ACLs to explicity allow what someone is allowed to reach and talk to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Levels are to provide granularity and set the security levels between zones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Jul 2010 21:52:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501824#M417423</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-07-24T21:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA recommended security levels in a data center</title>
      <link>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501825#M417424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx for the useful info!&lt;/P&gt;&lt;P&gt;IF servers are dynamically opening ports for specific applications in return to client requests, should I use the established command or placing users in lower security levels can do the job?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 07:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-recommended-security-levels-in-a-data-center/m-p/1501825#M417424</guid>
      <dc:creator>k.abillama</dc:creator>
      <dc:date>2010-07-26T07:00:02Z</dc:date>
    </item>
  </channel>
</rss>

