<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Same security interface not passing traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781889#M971209</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The code it build to don't allow communication between interface with same security level even if you have ACL's allowing the traffic. One interesting point is that th e ASA/PIX behave different than the FWSM when use same-security-interface command. As acomiskey said when use the same-security-interface it allows communication without ACL's in the FWSM after enable the same-security-interface it still need ACL's. Another option for you could change the security level in one of the interface with level 50 to something 51 or 49 and then add ACL's to allow traffic between those 2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Aug 2007 17:12:54 GMT</pubDate>
    <dc:creator>rigoberto.cintron</dc:creator>
    <dc:date>2007-08-15T17:12:54Z</dc:date>
    <item>
      <title>Same security interface not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781882#M971202</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 525 that has 8 interfaces, inside, outside,  2 security level 75 and 4 security level 50.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic from interfaces on security level 50 must not be allowed to other security level 50 interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic from interfaces on security level 75 interfaces is allowed to other security level 75 interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Therefore, I'd rather not enable the same-security-interface-permit command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured ACL's on the security level 75 interfaces to permit traffic to flow, but it doesn't appear to be working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I change the security level on one of the level 75 interfaces to 76, then traffic flows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:58:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781882#M971202</guid>
      <dc:creator>lee.messenger</dc:creator>
      <dc:date>2019-03-11T10:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Same security interface not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781883#M971203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about enabling same-security-traffic permit inter-interface then writing acls to prevent the traffic from the level 50 interfaces.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2007 13:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781883#M971203</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-08-15T13:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Same security interface not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781884#M971204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you use same-security-traffic permit inter-interface feature you still have to create acl's to allow the traffic between the interface. The same-security-traffic permit inter-interface feature basically allow the firewall use the acl's that you create to allow traffic between interface with same security levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/intfce_f.html#wp1039276" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/intfce_f.html#wp1039276&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2007 13:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781884#M971204</guid>
      <dc:creator>rigoberto.cintron</dc:creator>
      <dc:date>2007-08-15T13:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Same security interface not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781885#M971205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's not what the ASA Command Ref. says...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Allowing communication between same security interfaces (enabled by the same-security-traffic inter-interface command) provides the following benefits: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- You can allow traffic to flow freely between all same security interfaces WITHOUT access lists."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2007 14:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781885#M971205</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-08-15T14:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Same security interface not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781886#M971206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I realise I could enable "same-security" but then I have to put denies in 4 ACLs and it starts to get more complex.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I'm really trying to find out is why hosts on different interfaces that have the same security level cannot communicate even though the ACL permits it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I have to have an ACL for the reply traffic as well perhaps ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also agree that you should not have to add ACL's if "same-security" is turned on.  Or perhaps that only applies for the ASA and not the Pix ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any more thoughts greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2007 15:25:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781886#M971206</guid>
      <dc:creator>lee.messenger</dc:creator>
      <dc:date>2007-08-15T15:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Same security interface not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781887#M971207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"What I'm really trying to find out is why hosts on different interfaces that have the same security level cannot communicate even though the ACL permits it."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Because you have not enabled the same-security-traffic command. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Do I have to have an ACL for the reply traffic as well perhaps?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-No.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2007 16:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781887#M971207</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-08-15T16:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Same security interface not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781888#M971208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So just to clarify then, as I must have misunderstood the configuration guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order for hosts on interfaces of the same security level to communicate,  the same-security-interface command must be enabled, even if there are ACL's defined which permit the communication ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2007 16:55:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781888#M971208</guid>
      <dc:creator>lee.messenger</dc:creator>
      <dc:date>2007-08-15T16:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Same security interface not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781889#M971209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The code it build to don't allow communication between interface with same security level even if you have ACL's allowing the traffic. One interesting point is that th e ASA/PIX behave different than the FWSM when use same-security-interface command. As acomiskey said when use the same-security-interface it allows communication without ACL's in the FWSM after enable the same-security-interface it still need ACL's. Another option for you could change the security level in one of the interface with level 50 to something 51 or 49 and then add ACL's to allow traffic between those 2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2007 17:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781889#M971209</guid>
      <dc:creator>rigoberto.cintron</dc:creator>
      <dc:date>2007-08-15T17:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Same security interface not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781890#M971210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks guys,  thats answered my questions now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2007 17:33:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-security-interface-not-passing-traffic/m-p/781890#M971210</guid>
      <dc:creator>lee.messenger</dc:creator>
      <dc:date>2007-08-15T17:33:00Z</dc:date>
    </item>
  </channel>
</rss>

