<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow traffic to pass between 2 same security level interfac in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953148#M954292</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok i have entered that command that you just told me and so far i have not had any problems. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the access-list that you told me about the next line as the same command but the interfaces are reversed. do i need to have this command entered as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"nat (mci) 0 access-list mci_nat0_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Apr 2008 18:04:24 GMT</pubDate>
    <dc:creator>sbohannan</dc:creator>
    <dc:date>2008-04-14T18:04:24Z</dc:date>
    <item>
      <title>Allow traffic to pass between 2 same security level interfaces</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953142#M954272</link>
      <description>&lt;P&gt;i have configured my ASA 5510 with 2 same level security interfaces, i have "Same-security-Traffic permit inter-interface" enabled on the asa, but no traffic either interfaces is passing to the other interface. I know this is an Access list problem but i can not find any commands to allow all traffic to pass freely between the 2 interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is greatly needed.&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;&lt;P&gt;Shane&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:31:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953142#M954272</guid>
      <dc:creator>sbohannan</dc:creator>
      <dc:date>2019-03-11T12:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953143#M954276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Access lists are not required when using inter-interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you getting a "no translation group" error message?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 16:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953143#M954276</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-04-14T16:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953144#M954279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes i am getting an no translation group error. &lt;/P&gt;&lt;P&gt;The exact error is -&lt;/P&gt;&lt;P&gt;No translation group found for icmp and for TCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have worked with one of the TAC engineers and the command that he gives me to correct this error grinds the network to a stand still. (Static (interface1,interface2) 172.16.0.0 172.16.0.0 netmask 255.255.0.0) if i enter this command all traffic slowly stops on interface 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 17:28:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953144#M954279</guid>
      <dc:creator>sbohannan</dc:creator>
      <dc:date>2008-04-14T17:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953145#M954282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That should be correct if...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface1 is 172.16.x.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you post a config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 17:34:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953145#M954282</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-04-14T17:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953146#M954286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have attached copy of my config. i do not understand why it stops network traffic when i put that command in. I have watched the network stop. i did try the command friday afternoon the network seem to recover after about 10 Min but the funny part of it all was i could not connect to some of the 172.16.0.0/16 servers and my partner could but he could not connect to the internet and i could.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe i have something amiss in the confige that i have not seen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shane&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 17:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953146#M954286</guid>
      <dc:creator>sbohannan</dc:creator>
      <dc:date>2008-04-14T17:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953147#M954289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You've already got &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_Nat0_outbound extended permit ip 172.16.0.0 255.255.0.0 192.199.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but what you are missing is...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_Nat0_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should work the same as that static command mentioned before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only other thing I see which may be an issue is whether or not the MCI interface will be able to route back to 172.16.0.0 via 192.199.1.254. You may have to do something other than nat exemption if that is the case. Something like...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no global (MCI) 100 interface&lt;/P&gt;&lt;P&gt;global (MCI) 101 interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 17:51:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953147#M954289</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-04-14T17:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953148#M954292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok i have entered that command that you just told me and so far i have not had any problems. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the access-list that you told me about the next line as the same command but the interfaces are reversed. do i need to have this command entered as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"nat (mci) 0 access-list mci_nat0_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 18:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953148#M954292</guid>
      <dc:creator>sbohannan</dc:creator>
      <dc:date>2008-04-14T18:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953149#M954294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe when you use "nat 0" with an access-list it is bidirectional. So adding the second command would technically be a duplication.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 18:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953149#M954294</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-04-14T18:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953150#M954296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from a computer on the 172.16.0.0/16 subnet i get the same error as i was before i put the command in that started traffic from the 192.199.1.0/24 subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 18:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953150#M954296</guid>
      <dc:creator>sbohannan</dc:creator>
      <dc:date>2008-04-14T18:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953151#M954298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me see if I've got this right...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.199.1.0 to 172.16.0.0 is working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.16.0.0 to 192.199.1.0 is not working?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 18:17:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953151#M954298</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-04-14T18:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953152#M954300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i did enter "nat (mci) 0 access-list mci_nat0_outbound" because they are running on different interfaces. it seems that all traffic is running as it should now. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so very much for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 18:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953152#M954300</guid>
      <dc:creator>sbohannan</dc:creator>
      <dc:date>2008-04-14T18:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to pass between 2 same security level interfac</title>
      <link>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953153#M954302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good deal. I guess the nat 0 is bidirectional only when using an access-list AND security levels are different. Thanks for teaching me something. Thanks for the rating.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 18:22:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-traffic-to-pass-between-2-same-security-level-interfaces/m-p/953153#M954302</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-04-14T18:22:12Z</dc:date>
    </item>
  </channel>
</rss>

