cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1283
Views
0
Helpful
4
Replies

ASA 5505 :: Does "same-security-traffic" make sense with base license?

newmindeye
Level 1
Level 1

Hey all.

Looks like at some point a Cisco TAC member added, "same-security-traffic permit intra-interface" to my config.  Since I have a base license, I only have 3 vlans (2 1/2 really): inside, outside and dmz, which are on security levels 100, 0, and 50, respectively.

What is the point of "same-security-traffic permit intra-interface" when each interface is on a different security level?

Basically, is there any reason at all to keep the rule in place or can I safely remove it?

Thanks

1 Accepted Solution

Accepted Solutions

Hi Noah,

Yes, you can very well delete it, it doesnt server any purpose of none if the interfaces are on same security levels.

Hope that helps.

Thanks,

Varun

Thanks,
Varun Rao

View solution in original post

4 Replies 4

varrao
Level 10
Level 10

Hi Noah,

It says "intra-interface" not "inter-interface". Intra-interface is used to u-turn the traffic when the source and destination are both behind teh same interface. If you have any such requirement , don't remove it otherwise you can.

Hope that helps.

Thanks,

Varun

Thanks,
Varun Rao

@Varun, thanks, but actual rule in place is, "same-security-traffic permit inter-interface"

Think I was googling and "intra" came up without my noticing it.

So, given that the rule is inter-interface, does it serve any purpose in my setup?

Hi Noah,

Yes, you can very well delete it, it doesnt server any purpose of none if the interfaces are on same security levels.

Hope that helps.

Thanks,

Varun

Thanks,
Varun Rao

done, removed, thanks ;-)

Review Cisco Networking for a $25 gift card