<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access denied by implicit rule in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3333614#M970357</link>
    <description>&lt;P&gt;Please share your configuration.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Feb 2018 14:03:11 GMT</pubDate>
    <dc:creator>Krash Mole</dc:creator>
    <dc:date>2018-02-19T14:03:11Z</dc:date>
    <item>
      <title>Access denied by implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3333579#M970356</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a Cisco ASA 5525-X running version&amp;nbsp;9.5(3)9.&lt;/P&gt;
&lt;P&gt;I encountered a kind of weird issue regarding access-list.&lt;/P&gt;
&lt;P&gt;For what I know if you are coming from a higher security level going to low, you don't&amp;nbsp; need to explicitly put an access-list to allow access.&lt;/P&gt;
&lt;P&gt;What happened to me is that my machines coming from the inside is denied by the implicit deny rule.&lt;/P&gt;
&lt;P&gt;NAT is configured properly, every other config is fine.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone of you experienced this?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3333579#M970356</guid>
      <dc:creator>ghermocilla</dc:creator>
      <dc:date>2020-02-21T15:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied by implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3333614#M970357</link>
      <description>&lt;P&gt;Please share your configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 14:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3333614#M970357</guid>
      <dc:creator>Krash Mole</dc:creator>
      <dc:date>2018-02-19T14:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied by implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3334029#M970358</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you can attach a packet-tracer output or syslogs, we can look into it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For a start, acl drop does not always means "access-list". It could be due to a variety of reasons like connection timeout etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;BR /&gt;AJ&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 05:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3334029#M970358</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-02-20T05:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied by implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3334059#M970448</link>
      <description>here's my config&lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet0/0.27&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 172.16.1.3 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.10 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;object network Inside-NAT&lt;BR /&gt; host 172.16.1.10&lt;BR /&gt;!&lt;BR /&gt;object-group network Inside-PC&lt;BR /&gt; network-object 10.100.1.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) source dynamic Inside-PC Inside-NAT&lt;BR /&gt;&lt;BR /&gt;It should work right? default behavior of firewall is to allow a higher security level to lower,&lt;BR /&gt;even without explicitly having an access-list</description>
      <pubDate>Tue, 20 Feb 2018 06:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3334059#M970448</guid>
      <dc:creator>ghermocilla</dc:creator>
      <dc:date>2018-02-20T06:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied by implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3334065#M970449</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="packet-tracer.JPG" style="width: 730px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/7791i93B75D1AD1A08D02/image-size/large?v=v2&amp;amp;px=999" role="button" title="packet-tracer.JPG" alt="packet-tracer.JPG" /&gt;&lt;/span&gt;that's the result for packet tracer, its being dropped, that why i need to explicitly put an access list like this one:&lt;/P&gt;
&lt;P&gt;access-list inside_access extended permit ip object-group Inside-PC any&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 07:02:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3334065#M970449</guid>
      <dc:creator>ghermocilla</dc:creator>
      <dc:date>2018-02-20T07:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied by implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3334089#M970450</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you already have an access-group configured, can you attach following outputs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show run access-group&amp;nbsp;&lt;SPAN&gt;inside_access&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show run access-list&amp;nbsp;&lt;SPAN&gt;inside_access&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideally, you should not require an access-list for traffic going from high security to low security interface.&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 08:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3334089#M970450</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-02-20T08:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied by implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3338074#M970451</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am also facing something similar.&lt;/P&gt;
&lt;P&gt;I have ASA 5545x series firewall running 9.8(2) version.&lt;/P&gt;
&lt;P&gt;Even after configuring the interfaces into access-group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The acls are not getting hit.&lt;/P&gt;
&lt;P&gt;Seems like the device is following the default behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advice ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I am missing something.&lt;/P&gt;
&lt;P&gt;Config :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface Management0/0&lt;BR /&gt; description Management interface connected to Port 3.&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt; management-only&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 90&lt;BR /&gt; ip address 172.20.40.10 255.255.255.0 standby 172.20.40.11&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-group management_access_in in interface management&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list management_access_in extended permit icmp any any&lt;BR /&gt;access-list management_access_in extended permit tcp any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 18:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-denied-by-implicit-rule/m-p/3338074#M970451</guid>
      <dc:creator>ciscoinfo</dc:creator>
      <dc:date>2018-02-26T18:00:55Z</dc:date>
    </item>
  </channel>
</rss>

