<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cisco asa5510 same security levels in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403542#M728638</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the wrong information.&lt;/P&gt;&lt;P&gt;Vijaya is 100% correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/intrface.html#wp1061479"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/intrface.html#wp1061479&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Mar 2010 13:33:03 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2010-03-16T13:33:03Z</dc:date>
    <item>
      <title>cisco asa5510 same security levels</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403537#M728605</link>
      <description>&lt;P&gt;Setting&amp;nbsp; up asa5510 - i have six interfaces.&amp;nbsp; Had planned on putting them all at the same secuirty level and then using ACL;s to allow specific traffic.&amp;nbsp; However I haven;t been able to get any traffic through any ports even with permit ip any to any on both in boudn and outbound.&amp;nbsp; I do not have same security level statement in running config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; is it possible to setup all interfaces at same secuirty level as I ahve them adn then use ACL;s to restrict traffic.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; if so Do i have to put aCL on both in and outboudn for every interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:21:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403537#M728605</guid>
      <dc:creator>jschweng</dc:creator>
      <dc:date>2019-03-11T17:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa5510 same security levels</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403538#M728616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have the same security permit inter-interface command, then you can establish communication between interfaces with the same security level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have 101 possible security levels that you can use (0-100), why would you want to put all 6 interfaces in the same security level?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you chose to have the 6 interfaces with the same security level, you can do that, and restrict traffic based on ACLs.&lt;/P&gt;&lt;P&gt;An inbound ACL on each interface where you want to restrict traffic is enough.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Mar 2010 04:17:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403538#M728616</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-03-15T04:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa5510 same security levels</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403539#M728622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if I have interfaces at the same security level and turn on "same-secuirty-traffic permit inter-interface"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then create inbound ACL's for those interfaces - will the firewall check those ACL's or just pass all the traffic between the same security interfaces?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Mar 2010 13:46:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403539#M728622</guid>
      <dc:creator>jschweng</dc:creator>
      <dc:date>2010-03-15T13:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa5510 same security levels</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403540#M728626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA will always check the inbound ACL for the traffic originated via that interface between any kind of interfaces&lt;/P&gt;&lt;P&gt; (even if they have or do not have the same security level)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Mar 2010 16:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403540#M728626</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-03-15T16:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa5510 same security levels</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403541#M728633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall BYPASSES interface access-list check for traffic between two different interfaces with same-security whenever&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-secuirty-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is turned ON. You can verify the same by looking at hitcounts of interface ACLs (show access-list) after initiating traffic between two hosts on same-sec &lt;STRONG&gt;DIfferent&lt;/STRONG&gt; interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you have Identity NAT from subnets to allow communication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vijaya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2010 05:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403541#M728633</guid>
      <dc:creator>vilaxmi</dc:creator>
      <dc:date>2010-03-16T05:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa5510 same security levels</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403542#M728638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the wrong information.&lt;/P&gt;&lt;P&gt;Vijaya is 100% correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/intrface.html#wp1061479"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/intrface.html#wp1061479&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2010 13:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403542#M728638</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-03-16T13:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa5510 same security levels</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403543#M728645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vijaya I used PIX635 and use same security level and there is no command of same security &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt; I guess it will not work in that and no ways to do &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bye,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Sep 2013 02:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5510-same-security-levels/m-p/1403543#M728645</guid>
      <dc:creator>Anand Solgama</dc:creator>
      <dc:date>2013-09-21T02:14:11Z</dc:date>
    </item>
  </channel>
</rss>

