<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix no longer permitting traffic from higher to lower priori in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-no-longer-permitting-traffic-from-higher-to-lower-priority/m-p/295300#M611911</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. I presently have a TAC case open. The traffic in question is outbound traffic from the DMZ to the outside interface. The server has a corresponding public static nat statement, but is unable to transmit traffic. In troubleshooting, I have found if I configure and access list, then traffic is permitted. However, I thought an access-list was not required as the traffic is implicitly permitted from a higher to lower priority interface. I have researched it and found this link, which the information in the subtobic "Allowing Outbound Access" confirms my thoughts. So, could this be a caveat in the code?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/warp/public/707/28.html#intro" target="_blank"&gt;http://cisco.com/warp/public/707/28.html#intro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Nov 2003 22:13:52 GMT</pubDate>
    <dc:creator>brad.hammond</dc:creator>
    <dc:date>2003-11-05T22:13:52Z</dc:date>
    <item>
      <title>Pix no longer permitting traffic from higher to lower priority</title>
      <link>https://community.cisco.com/t5/network-security/pix-no-longer-permitting-traffic-from-higher-to-lower-priority/m-p/295298#M611903</link>
      <description>&lt;P&gt;In release 6.3.3, does the pix no longer implicitly permit traffic from a higher priority interface to a lower priority interface other than the respective inside and outside interfaces? Or, is this a caveat in the code itself? For some reason, I am now required to configure an access list for device on a perimeter interface or DMZ for any external traffic the device initiates to Internet host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:04:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-no-longer-permitting-traffic-from-higher-to-lower-priority/m-p/295298#M611903</guid>
      <dc:creator>brad.hammond</dc:creator>
      <dc:date>2020-02-21T07:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Pix no longer permitting traffic from higher to lower priori</title>
      <link>https://community.cisco.com/t5/network-security/pix-no-longer-permitting-traffic-from-higher-to-lower-priority/m-p/295299#M611905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order pass traffic from a lower security level interface to a higher security level interface (outside to inside or dmz, or dmz to inside) you must create a static address translation and an access list.  In order to travel the other direction (inside or dmz to outside) you must use a nat and global command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2003 21:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-no-longer-permitting-traffic-from-higher-to-lower-priority/m-p/295299#M611905</guid>
      <dc:creator>daniel.kline</dc:creator>
      <dc:date>2003-11-05T21:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Pix no longer permitting traffic from higher to lower priori</title>
      <link>https://community.cisco.com/t5/network-security/pix-no-longer-permitting-traffic-from-higher-to-lower-priority/m-p/295300#M611911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. I presently have a TAC case open. The traffic in question is outbound traffic from the DMZ to the outside interface. The server has a corresponding public static nat statement, but is unable to transmit traffic. In troubleshooting, I have found if I configure and access list, then traffic is permitted. However, I thought an access-list was not required as the traffic is implicitly permitted from a higher to lower priority interface. I have researched it and found this link, which the information in the subtobic "Allowing Outbound Access" confirms my thoughts. So, could this be a caveat in the code?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/warp/public/707/28.html#intro" target="_blank"&gt;http://cisco.com/warp/public/707/28.html#intro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2003 22:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-no-longer-permitting-traffic-from-higher-to-lower-priority/m-p/295300#M611911</guid>
      <dc:creator>brad.hammond</dc:creator>
      <dc:date>2003-11-05T22:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Pix no longer permitting traffic from higher to lower priori</title>
      <link>https://community.cisco.com/t5/network-security/pix-no-longer-permitting-traffic-from-higher-to-lower-priority/m-p/295301#M611914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post your config?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2003 00:21:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-no-longer-permitting-traffic-from-higher-to-lower-priority/m-p/295301#M611914</guid>
      <dc:creator>bfl1</dc:creator>
      <dc:date>2003-11-06T00:21:54Z</dc:date>
    </item>
  </channel>
</rss>

