<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic quick question about interface security levels in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/quick-question-about-interface-security-levels/m-p/1614458#M595306</link>
    <description>&lt;P&gt;as i understand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by default...any interface with a higher security leveil..i.e 100 is automatically allowed to lower..i.e 40, 0, 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and lower is denied to higher&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;howerver on my asa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have an inside interface with a security level of 100 and deviced behind that (our inside network)&lt;/P&gt;&lt;P&gt;trying to talk to a server in the app dmz level 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it is denied by the inside interface acl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only when i apply the acl to allow our inside host to talk to the dmz server will this go through..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that doesnt makes sense..shouldn't it be allowed&amp;nbsp; by default even thought there is an implicit deny any rule at the end of the rule set?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:30:17 GMT</pubDate>
    <dc:creator>nygenx2011</dc:creator>
    <dc:date>2019-03-11T19:30:17Z</dc:date>
    <item>
      <title>quick question about interface security levels</title>
      <link>https://community.cisco.com/t5/network-security/quick-question-about-interface-security-levels/m-p/1614458#M595306</link>
      <description>&lt;P&gt;as i understand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by default...any interface with a higher security leveil..i.e 100 is automatically allowed to lower..i.e 40, 0, 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and lower is denied to higher&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;howerver on my asa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have an inside interface with a security level of 100 and deviced behind that (our inside network)&lt;/P&gt;&lt;P&gt;trying to talk to a server in the app dmz level 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it is denied by the inside interface acl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only when i apply the acl to allow our inside host to talk to the dmz server will this go through..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that doesnt makes sense..shouldn't it be allowed&amp;nbsp; by default even thought there is an implicit deny any rule at the end of the rule set?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quick-question-about-interface-security-levels/m-p/1614458#M595306</guid>
      <dc:creator>nygenx2011</dc:creator>
      <dc:date>2019-03-11T19:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: quick question about interface security levels</title>
      <link>https://community.cisco.com/t5/network-security/quick-question-about-interface-security-levels/m-p/1614459#M595308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;nygenx2011 wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt; &lt;P&gt;&lt;/P&gt;&lt;P&gt;and it is denied by the inside interface acl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only when i apply the acl to allow our inside host to talk to the dmz server will this go through..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that doesnt makes sense..shouldn't it be allowed&amp;nbsp; by default even thought there is an implicit deny any rule at the end of the rule set?&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right by default , the traffic from a higher sec level to a lower sec level is permited = this mean if there is no access-list applied.&lt;/P&gt;&lt;P&gt;If you apply the access-list , this dont cover the default behavior, and you should permit the traffic that you need to pass.&lt;/P&gt;&lt;P&gt;So the FW reaction is&amp;nbsp; as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jan 2011 18:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quick-question-about-interface-security-levels/m-p/1614459#M595308</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2011-01-04T18:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: quick question about interface security levels</title>
      <link>https://community.cisco.com/t5/network-security/quick-question-about-interface-security-levels/m-p/1614460#M595310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 16:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quick-question-about-interface-security-levels/m-p/1614460#M595310</guid>
      <dc:creator>nygenxny123</dc:creator>
      <dc:date>2011-01-05T16:57:04Z</dc:date>
    </item>
  </channel>
</rss>

