05-14-2022 09:36 AM - edited 05-14-2022 10:28 AM
Hi All,
Is there a way where we can allow traffic from outside interface with security-level 0 to Inside or DMZ interface with higher security-level apart from ACLs ? I mean without any acl entry can we allow traffic?
Is there any other way traffic can be permitted from low level to high level without ACL Entry?
05-14-2022 09:46 AM
This make DMZ direct connect to out amd this make ASA useless.
You can bypass asa by connect dmz to out but again this make asa useless.
Can i ask why you want that?
05-14-2022 10:24 AM - edited 05-14-2022 10:25 AM
I have been asked this question in an interview by interviewer
05-14-2022 12:05 PM
@kalyanChakravarthy it depends what type of traffic. If the command sysopt connection permit-vpn is configured, then VPN traffic which is terminated on the outside interface bypasses the interface ACLs.
05-15-2022 02:01 PM
If this is regular through the box traffic then the answer is no. You must have an ACL to allow traffic to pass from a higher security level interface to a lower security level interface.
Now if this is a VPN setup then there is a possibility to allow VPN traffic to bypass the interface ACL (this is enabled by default on Cisco firewalls).
But without more context to the question you were asked by the interviewer, what I posted is the correct answer.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide