cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
692
Views
0
Helpful
1
Replies

ACL on ASASM

zhiqiang.yan
Level 1
Level 1

Hi,

I am reading the ASASM configuration guide.

About ACL, there is "Implicit Permits" that allows traffic from a higher secuity interface to a lower one. But on the other hand, "To allow any traffic to enter the ASASM, you must attach an inbound access rule to an interface; otherwise, the ASASM automatically drops all traffic that enters that interface."

This sounds confused. For example, if a context has only "inside" and "outside" interface, and I need permit all from "inside" and a filter for traffic from "outside". Then do I still need a "permit any" rule attach to the "inside" interface?

Thanks,

1 Accepted Solution

Accepted Solutions

varrao
Level 10
Level 10

Hi,

Yes you are correct, the concept is different on ASA and ASASM.

On ASA, you dont need any ACL, if the traffic is going from inside to outside(higher to lower), beacuse there is an implicit allow acl.

On ASASM, you would definitely need an acl, if you are going from lower to higher security or from higher to lower security, ACL is very much needed.

Do let me know if you have any queries.

Thanks,

Varun

Thanks,
Varun Rao

View solution in original post

1 Reply 1

varrao
Level 10
Level 10

Hi,

Yes you are correct, the concept is different on ASA and ASASM.

On ASA, you dont need any ACL, if the traffic is going from inside to outside(higher to lower), beacuse there is an implicit allow acl.

On ASASM, you would definitely need an acl, if you are going from lower to higher security or from higher to lower security, ACL is very much needed.

Do let me know if you have any queries.

Thanks,

Varun

Thanks,
Varun Rao
Review Cisco Networking for a $25 gift card