<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic same security level rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/same-security-level-rules/m-p/1312856#M859202</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I came across some interface on our firewall with same security level &amp;amp; also ACE corresponding to each of these interfaces.&lt;/P&gt;&lt;P&gt;I also found that "same security level command" has been enabled on the firewall. &lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;If 2 interfaces with same level say 50 need to pass traffic between each other, do they still require rules with above command enabled?&lt;/P&gt;&lt;P&gt;If i remove the rules and test the traffic , would it allow traffic between these interfaces based on above command?&lt;/P&gt;&lt;P&gt;Please suggest.Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:46:14 GMT</pubDate>
    <dc:creator>suthomas1</dc:creator>
    <dc:date>2019-03-11T15:46:14Z</dc:date>
    <item>
      <title>same security level rules</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-rules/m-p/1312856#M859202</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I came across some interface on our firewall with same security level &amp;amp; also ACE corresponding to each of these interfaces.&lt;/P&gt;&lt;P&gt;I also found that "same security level command" has been enabled on the firewall. &lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;If 2 interfaces with same level say 50 need to pass traffic between each other, do they still require rules with above command enabled?&lt;/P&gt;&lt;P&gt;If i remove the rules and test the traffic , would it allow traffic between these interfaces based on above command?&lt;/P&gt;&lt;P&gt;Please suggest.Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:46:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-rules/m-p/1312856#M859202</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T15:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: same security level rules</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-rules/m-p/1312857#M859204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the interfaces are configured with identical security levels, you have the "same-security-traffic permit inter-interface" command enabled, and you are running 7.2 or later code, you'll need to have specific rules to pass traffic in each direction between the segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jun 2009 00:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-rules/m-p/1312857#M859204</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2009-06-22T00:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: same security level rules</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-rules/m-p/1312858#M859206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that means even with this command, rules still have to be there.&lt;/P&gt;&lt;P&gt;Then what purpose does this command serve?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jun 2009 06:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-rules/m-p/1312858#M859206</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2009-06-22T06:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: same security level rules</title>
      <link>https://community.cisco.com/t5/network-security/same-security-level-rules/m-p/1312859#M859208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Without the command enabled, traffic WILL NOT pass between two segments with identical security levels even if access-lists are configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the command enabled, traffic WILL pass between the segments but must be permitted via an access-list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jun 2009 18:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-level-rules/m-p/1312859#M859208</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2009-06-22T18:19:47Z</dc:date>
    </item>
  </channel>
</rss>

