<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security levels on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-levels-on-asa/m-p/1302219#M824072</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have you tried enabling the same level intra-interface communications. Here's a link all about it:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname(config)# &lt;STRONG class="cBold"&gt;same-security-traffic permit inter-interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Dec 2009 12:06:34 GMT</pubDate>
    <dc:creator>johnbroadway</dc:creator>
    <dc:date>2009-12-02T12:06:34Z</dc:date>
    <item>
      <title>Security levels on ASA</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-on-asa/m-p/1302218#M824070</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to allow traffic between 2 VLAN's/sub interfaces on my ASA, the both have their security Level set at 25.&amp;nbsp; At the moment I can't even ping devices between the 2 and my access lists are wide open.&amp;nbsp; I raised one of the security groups to 35 and everything seem to work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm left a little confused, if security levels are the same are the untrusted?&amp;nbsp; What ever I did on the access list side (to open it up) seemed to be ignored.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:44:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-on-asa/m-p/1302218#M824070</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2019-03-11T16:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security levels on ASA</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-on-asa/m-p/1302219#M824072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have you tried enabling the same level intra-interface communications. Here's a link all about it:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname(config)# &lt;STRONG class="cBold"&gt;same-security-traffic permit inter-interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Dec 2009 12:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-on-asa/m-p/1302219#M824072</guid>
      <dc:creator>johnbroadway</dc:creator>
      <dc:date>2009-12-02T12:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Security levels on ASA</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-on-asa/m-p/1302220#M824076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this commonly enable by most, I set both these sub interfaces to the same as they sort of need resources from each, have the same security set like you mention is a good idea in my eyes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Dec 2009 12:33:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-on-asa/m-p/1302220#M824076</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2009-12-02T12:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Security levels on ASA</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-on-asa/m-p/1302221#M824081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a fairly new option (I think since V7 ish) for your sort of instance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If both interfaces require resources from the other then it seems a reasonable approach to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Dec 2009 12:45:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-on-asa/m-p/1302221#M824081</guid>
      <dc:creator>johnbroadway</dc:creator>
      <dc:date>2009-12-02T12:45:48Z</dc:date>
    </item>
  </channel>
</rss>

