<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Same security level interface ACL in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782476#M493540</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first rule to be hit will always be the same-security-traffic implicit rule. If you want to filter this you can do one of 2 things. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-Lower one of the interfaces security levels and use ACLs to permit the traffic &lt;/P&gt;&lt;P&gt;2-Put the command same-security-traffic permit inter-interface and then filter the traffic between them using ACLs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a third one, but is related to NAT and since you dont have nat configured it will be better to leave it as it is. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Nov 2011 21:51:31 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2011-11-14T21:51:31Z</dc:date>
    <item>
      <title>Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782467#M493531</link>
      <description>&lt;P&gt;On a Cisco ASA 5520. &amp;nbsp;I have 2 interfaces that are the same security level. I need hosts on 1 of these interfaces to be able to get to a specific IP and port on the other but I DON'T want to blanket enable 'same-security-traffic permit inter-interface" &amp;nbsp;I have added an ACL inbound on the interface allowing the desired traffic and inbound on the other for return traffic and it simply doesn't work. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3.175&lt;/P&gt;&lt;P&gt;&amp;nbsp;vlan 175 &amp;nbsp; &amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif Test175&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 30&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 172.30.175.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3.185&lt;/P&gt;&lt;P&gt;&amp;nbsp;vlan 185&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif Test185&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 30&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 172.30.185.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list Test185 extended permit udp any host 172.20.175.52 eq ntp &lt;/P&gt;&lt;P&gt;access-group Test185 in interface Test185&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list Test175 extended permit udp host 172.20.175.52 eq ntp any&lt;/P&gt;&lt;P&gt;access-group Test175 in interface Test175&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782467#M493531</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2019-03-11T21:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782468#M493532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post your whole config? Need to look at your NAT policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Nov 2011 04:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782468#M493532</guid>
      <dc:creator>vabruno</dc:creator>
      <dc:date>2011-11-12T04:25:32Z</dc:date>
    </item>
    <item>
      <title>Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782469#M493533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, may be NAT need to be disabled for the communication between these two interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post your configuration&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Nov 2011 04:32:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782469#M493533</guid>
      <dc:creator>vipinrajrc</dc:creator>
      <dc:date>2011-11-12T04:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782470#M493534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no NAT between the two. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Nov 2011 04:32:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782470#M493534</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2011-11-12T04:32:30Z</dc:date>
    </item>
    <item>
      <title>Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782471#M493535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I move the source interface up a security level it works so it's not NAT related as the source interface has no NAT configurations. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Nov 2011 04:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782471#M493535</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2011-11-12T04:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782472#M493536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;may all of your LAN is PATed to the public IP(or interface). Then you should exclude NAT for the communication between these two interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Vipin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Nov 2011 04:36:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782472#M493536</guid>
      <dc:creator>vipinrajrc</dc:creator>
      <dc:date>2011-11-12T04:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782473#M493537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;VPN# packet-tracer input JMSTest185 udp 172.30.85.10 123 172.30.175.52 123 det&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0x7b4060b0, priority=1, domain=permit, deny=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=2612, user_data=0x0, cs_id=0x0, l3_type=0x8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src mac=0000.0000.0000, mask=0000.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst mac=0000.0000.0000, mask=0100.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=JMSTest185, output_ifc=any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 172.30.175.0&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; JMS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0x79336a28, priority=11, domain=permit, deny=true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=1365, user_data=0x5, cs_id=0x0, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip/id=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=JMSTest185, output_ifc=any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: JMSTest185&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: JMS&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Nov 2011 04:42:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782473#M493537</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2011-11-12T04:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782474#M493538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I notice in the packet tracer you used 172.30.85.10 as your source address but the interface uses 172.30.185.0/24.&amp;nbsp; Is this the correct host and if so, is there a route for the 172.30.85.X network on the JMSTest185 interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is NAT control enabled?&amp;nbsp; With the 'same-security-traffic permit inter-interface' command in place, traffic should be allowed to traverse the two same-security interfaces without NAT (even if NAT control is enabled) as long as the correct access-list entries are in place.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 21:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782474#M493538</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2011-11-14T21:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782475#M493539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&amp;nbsp; You are right.&amp;nbsp; But with the correct IP it still fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0x79336a28, priority=11, domain=permit, deny=true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=2837, user_data=0x5, cs_id=0x0, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip/id=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=JMSTest185, output_ifc=any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 21:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782475#M493539</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2011-11-14T21:33:34Z</dc:date>
    </item>
    <item>
      <title>Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782476#M493540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first rule to be hit will always be the same-security-traffic implicit rule. If you want to filter this you can do one of 2 things. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-Lower one of the interfaces security levels and use ACLs to permit the traffic &lt;/P&gt;&lt;P&gt;2-Put the command same-security-traffic permit inter-interface and then filter the traffic between them using ACLs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a third one, but is related to NAT and since you dont have nat configured it will be better to leave it as it is. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 21:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782476#M493540</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-14T21:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782477#M493541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So wait, is the packet-tracer output you provided with'same-security-traffic permit inter-interface' enabled?&amp;nbsp; The packet-tracer output is what I would expect to see without the command.&amp;nbsp; It has to be there if you want to leave the security levels the way they are. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 21:52:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782477#M493541</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2011-11-14T21:52:23Z</dc:date>
    </item>
    <item>
      <title>Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782478#M493542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm kinda suprised there isn't a way to allow the traffic via an ACL...&amp;nbsp; Thanks everyone for your input.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 22:09:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782478#M493542</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2011-11-14T22:09:27Z</dc:date>
    </item>
    <item>
      <title>Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782479#M493543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is, but you will need to add the same security traffic first. That would be the first rule to be hitted, then what you need to do is to filter the rest with ACLs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 23:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782479#M493543</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-14T23:28:55Z</dc:date>
    </item>
    <item>
      <title>Same security level interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782480#M493544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you dont want an other host to communicate with any other IP on the same security level interface you can use ACL to limit this, and then use same security-level inter-interface command and life remains good, if I understand logic of not using&amp;nbsp; the command .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Nov 2011 18:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-interface-acl/m-p/1782480#M493544</guid>
      <dc:creator>mudjain</dc:creator>
      <dc:date>2011-11-25T18:08:46Z</dc:date>
    </item>
  </channel>
</rss>

