<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190467#M874615</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bruce&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be a number of things. Also the transit vlan - are you using contexts on the FWSM's ?. If not a quick schematic of the layout would be useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You haven't mentioned what the acl for vlan 2 is and also you haven't mentioned anything about NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Mar 2009 21:14:45 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2009-03-25T21:14:45Z</dc:date>
    <item>
      <title>ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190466#M874614</link>
      <description>&lt;P&gt;I'm attempting to provide access from one FWSM to another, using VLAN's and ACL's.  the purpose is to allow a set of servers behind one firewall, to use DNS appliances behind another firewall.  Here is some basic config info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FIREWALL A = VLAN 1 - Host VLAN&lt;/P&gt;&lt;P&gt;FIREWALL B = VLAN 2 - DNS Appliance VLAN&lt;/P&gt;&lt;P&gt;FIREWALL A&amp;amp;B VLAN 3 - Transit VLAN between 2 FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL is open to VLAN 1, allowing port 53 TCP/UDP connections from all hosts in the subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL is open to VLAN 3, allowing the traffic through the interface at FW-B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to observe the traffic (through captures) up through VLAN 3.  Once I start capturing on FW-B VLAN 2, I see nothing.  No traffic at all...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts off hand?  something I've missed?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:10:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190466#M874614</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2019-03-11T15:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190467#M874615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bruce&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be a number of things. Also the transit vlan - are you using contexts on the FWSM's ?. If not a quick schematic of the layout would be useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You haven't mentioned what the acl for vlan 2 is and also you haven't mentioned anything about NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 21:14:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190467#M874615</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-03-25T21:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190468#M874616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are using static statements for advertising the networks...we are using contexts on the FWSM's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the interface at the transit vlan 3 and the interface on vlan 2 are same security levels and I'm thinking I dont need an ACL at that point.  Is that thinking correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bruce&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 21:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190468#M874616</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2009-03-25T21:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190469#M874617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bruce&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes traffic will flow between interfaces of the same security level with the same security level as long as you have added to the config - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However this is only relevant per context. I'm still not clear whether this setup is utilising one or more contexts ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 21:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190469#M874617</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-03-25T21:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190470#M874618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, 2 contexts...I'm sorry...FW-B (DNS Appliances) uses a default context and FW-A (servers) uses a configured context (not default).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the same-security-traffic config you refer to is not setup on FW-B, however, &lt;/P&gt;&lt;P&gt;there is another group of servers that reside on FW-B, in VLAN 4 that ARE able to access the DNS appliances in VLAN 2...AND the interface VLAN 4 is a lower security level than VLAN 2...That is what is confusing me about this issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the only ACL that is applied to VLAN 2's interface is allows return traffic from the DNS appliances to any "querying" server...defined below...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list VLAN2 extended permit udp &lt;PUBLIC addy=""&gt; any eq domain &lt;/PUBLIC&gt;&lt;/P&gt;&lt;P&gt;access-list VLAN2 extended permit tcp &lt;PUBLIC addy=""&gt; any eq domain &lt;/PUBLIC&gt;&lt;/P&gt;&lt;P&gt;access-list VLAN2 extended permit icmp &lt;PUBLIC addy=""&gt; any &lt;/PUBLIC&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 22:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-issue/m-p/1190470#M874618</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2009-03-25T22:07:25Z</dc:date>
    </item>
  </channel>
</rss>

