<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Modular Policy Framework - Global vs. Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744178#M533497</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, that does clear my doubts about this.&amp;nbsp; Instinctively, I thought that it worked like that, but I could not find anything in the documenatation, or an example that confirmed it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Aug 2011 12:39:57 GMT</pubDate>
    <dc:creator>pncisco216</dc:creator>
    <dc:date>2011-08-16T12:39:57Z</dc:date>
    <item>
      <title>ASA Modular Policy Framework - Global vs. Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744176#M533493</link>
      <description>&lt;P&gt;I understand from the Cisco documentation that a service-policy applied to an interface on an ASA 5500 series firewall, will override the default global service-policy.&amp;nbsp; However, I am not clear on whether it will override the entire global service-policy, or only the parts where they overlap.&amp;nbsp; In other words, would the resulting service-policy on the interface in question be just what was applied in the service-policy on the interface, completely replacing the global service-policy?&amp;nbsp; Or, would it be a combination of the global and interface service-policies, with the interface one taking precedence where they overlap?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I wanted an interface to have the same service-policy as the global service-policy plus on other item, can I just add the one item in a service-policy that I apply to the interface, or do I have to replicate all the items from the global policy, plus the one additional item, and apply that to the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744176#M533493</guid>
      <dc:creator>pncisco216</dc:creator>
      <dc:date>2019-03-11T21:11:56Z</dc:date>
    </item>
    <item>
      <title>ASA Modular Policy Framework - Global vs. Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744177#M533495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/partner/i/templates/blank.gif" width="19" /&gt;&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp; service policies take precedence over the global service policy for a&amp;nbsp; given feature. For example, if you have a global policy with FTP&amp;nbsp; inspection, and an interface policy with TCP normalization, then both&amp;nbsp; FTP inspection and TCP normalization are applied to the interface.&amp;nbsp; However, if you have a global policy with FTP inspection, and an&amp;nbsp; interface policy with FTP inspection, then only the interface policy FTP&amp;nbsp; inspection is applied to that interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a doc for detailed study:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/security/asa/asa82/configuration/guide/mpf.html"&gt;http://www.cisco.com/en/US/partner/docs/security/asa/asa82/configuration/guide/mpf.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this clears out your doubt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 07:19:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744177#M533495</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-16T07:19:40Z</dc:date>
    </item>
    <item>
      <title>ASA Modular Policy Framework - Global vs. Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744178#M533497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, that does clear my doubts about this.&amp;nbsp; Instinctively, I thought that it worked like that, but I could not find anything in the documenatation, or an example that confirmed it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 12:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744178#M533497</guid>
      <dc:creator>pncisco216</dc:creator>
      <dc:date>2011-08-16T12:39:57Z</dc:date>
    </item>
    <item>
      <title>ASA Modular Policy Framework - Global vs. Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744179#M533498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad I could help &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 13:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744179#M533498</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-16T13:07:44Z</dc:date>
    </item>
    <item>
      <title>ASA Modular Policy Framework - Global vs. Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744180#M533499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply! &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;And what if Cisco ASA is configured with global policy and interface policy. Both policies have ftp inspection and traffic does not match class map for interface policy, but match class map for global policy. Will such traffic be inspected by global policy?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Feb 2014 08:13:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-modular-policy-framework-global-vs-interface/m-p/1744180#M533499</guid>
      <dc:creator>Frantsuz21</dc:creator>
      <dc:date>2014-02-05T08:13:40Z</dc:date>
    </item>
  </channel>
</rss>

