<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic ASA ACL Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/basic-asa-acl-question/m-p/1613310#M564264</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response. Could you clarify what you mean by "only the first connection needs to be allowed with an ACL if you have applied an ACL on the interface."? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My assumption is you are refering to traffic moving from the outside interface in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if an acl is applied to the outside interface permitting traffic to an inside interface the acl will allow the connection, then all subsequent packets matching the rule will be cef switched?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Newt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Mar 2011 23:26:08 GMT</pubDate>
    <dc:creator>newtwork1</dc:creator>
    <dc:date>2011-03-08T23:26:08Z</dc:date>
    <item>
      <title>Basic ASA ACL Question</title>
      <link>https://community.cisco.com/t5/network-security/basic-asa-acl-question/m-p/1613308#M564262</link>
      <description>&lt;P&gt;I understand that all traffic from the inside int to the outside int is allowed by default (if the security level of the inside interface is higher than the outside interface). Does that rule apply bi-directionally or do I need to create a rule that will allow all return traffic originating from the inside interface to the outside back IN through an ACE applied to the ouside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Newt.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-asa-acl-question/m-p/1613308#M564262</guid>
      <dc:creator>newtwork1</dc:creator>
      <dc:date>2019-03-11T20:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Basic ASA ACL Question</title>
      <link>https://community.cisco.com/t5/network-security/basic-asa-acl-question/m-p/1613309#M564263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The return traffic for traffic originated from inside towards outside is allowed automatically, ie: you do not need to configure ACL to allow the return traffic on the outside interface. ASA keeps tracks of all the connections hence only the first connection needs to be allowed with an ACL if you have applied an ACL on the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Mar 2011 06:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-asa-acl-question/m-p/1613309#M564263</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-03-06T06:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Basic ASA ACL Question</title>
      <link>https://community.cisco.com/t5/network-security/basic-asa-acl-question/m-p/1613310#M564264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response. Could you clarify what you mean by "only the first connection needs to be allowed with an ACL if you have applied an ACL on the interface."? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My assumption is you are refering to traffic moving from the outside interface in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if an acl is applied to the outside interface permitting traffic to an inside interface the acl will allow the connection, then all subsequent packets matching the rule will be cef switched?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Newt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Mar 2011 23:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-asa-acl-question/m-p/1613310#M564264</guid>
      <dc:creator>newtwork1</dc:creator>
      <dc:date>2011-03-08T23:26:08Z</dc:date>
    </item>
  </channel>
</rss>

