<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 &amp; same security level in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-same-security-level/m-p/711837#M426964</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After you add "same-security-traffic permit inter-interface", the next thing to do is to permit inside and wan to talk to each other. Example:&lt;/P&gt;&lt;P&gt;inside - 10.1.1.0/24&lt;/P&gt;&lt;P&gt;wan - 10.1.2.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,wan) 10.1.1.0 10.1.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;static (wan,inside) 10.1.2.0 10.1.2.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a008045247c.html#wp1009571" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a008045247c.html#wp1009571&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Oct 2006 14:05:55 GMT</pubDate>
    <dc:creator>a.kiprawih</dc:creator>
    <dc:date>2006-10-16T14:05:55Z</dc:date>
    <item>
      <title>ASA 5520 &amp; same security level</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-same-security-level/m-p/711836#M426961</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Have ASA 5520.&lt;/P&gt;&lt;P&gt;Giga0/0 nameif outside, sec 0 - to internet&lt;/P&gt;&lt;P&gt;Giga0/1 nameif inside, sec 100 - to lan&lt;/P&gt;&lt;P&gt;Giga 0/2 namif wan, sec 100 - to branch offces router.&lt;/P&gt;&lt;P&gt;I've aplied command same-security-traffic permit inter-interface, but no result. Can't access from one to another interface with the same security level.&lt;/P&gt;&lt;P&gt;At asdm log apears next message: No route from lan_ip_addr to wan_ip_addr.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you help me to resolve this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:14:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-same-security-level/m-p/711836#M426961</guid>
      <dc:creator>Andrei Scurupii</dc:creator>
      <dc:date>2020-02-21T09:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 &amp; same security level</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-same-security-level/m-p/711837#M426964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After you add "same-security-traffic permit inter-interface", the next thing to do is to permit inside and wan to talk to each other. Example:&lt;/P&gt;&lt;P&gt;inside - 10.1.1.0/24&lt;/P&gt;&lt;P&gt;wan - 10.1.2.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,wan) 10.1.1.0 10.1.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;static (wan,inside) 10.1.2.0 10.1.2.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a008045247c.html#wp1009571" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a008045247c.html#wp1009571&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2006 14:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-same-security-level/m-p/711837#M426964</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-10-16T14:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 &amp; same security level</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-same-security-level/m-p/711838#M426966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, thanks.. it works..  one more question&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;beside wan interface i have router with one int to ASA (10.1.2.x) and another to office (11.1.1.x).&lt;/P&gt;&lt;P&gt;From this router can ping lacal lan (10.1.1.0).&lt;/P&gt;&lt;P&gt;But then i ping with sourse int. 11.1.1.x - I cant ping lan. And at ASA logs apears: no route found  from 11.1.1.x to 10.1.1.x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2006 15:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-same-security-level/m-p/711838#M426966</guid>
      <dc:creator>Andrei Scurupii</dc:creator>
      <dc:date>2006-10-16T15:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 &amp; same security level</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-same-security-level/m-p/711839#M426968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In other words (correct me if I am wrong), the router has 2 FastE interfaces, one end connected to ASA and carry 10.1.2.x ip, while another FastE interface assigned with 11.1.1.x ip and connected to another 11.1.1.0 segment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can't ping it because your ASA does not recognised or can reach (route) 11.1.1.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ASA:&lt;/P&gt;&lt;P&gt;a. Add static route to the router:&lt;/P&gt;&lt;P&gt;   route wan 11.1.1.0 255.255.255.0 10.1.1.x&lt;/P&gt;&lt;P&gt;b. Permit icmp to wan interface from 11.1.1.x&lt;/P&gt;&lt;P&gt;   icmp permit host 11.1.1.x any wan  -or-&lt;/P&gt;&lt;P&gt;   icmp permit 11.1.1.0 255.255.255.0 any wan &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Optional:&lt;/P&gt;&lt;P&gt;On your router, if all access need to point back to ASA, then create default route to ASA (or add specific route):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.1.2.y --&amp;gt; ASA wan interface IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH. Pls rate all helpful posts.&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2006 16:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-same-security-level/m-p/711839#M426968</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-10-16T16:13:31Z</dc:date>
    </item>
  </channel>
</rss>

