cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
968
Views
5
Helpful
2
Replies

Can't over rule implicit deny any

jhonny.eriksson
Level 1
Level 1

Hello,

I just tried to over rule an implicit deny any any rule with an permit any any in my ASA but traffic keeps on hitting the last deny any rule. How can this be?

The interfaces have the same security levels (0). I also have an Permit any any in the other direction. The rules are enabled. Routing is OK. I can ping both destinations from the ASA. I have also enabled the traffic to pass between intra-subinterface;

same-security-traffic permit intra-interface

Thanks,

Best Regards

Jhonny Eriksson

2 Replies 2

Eugene Korneychuk
Cisco Employee
Cisco Employee

Hello Johnny,

Did you try

same-security-traffic permit inter-interface? Please let me know the result, also if it will not help, can you attach packet-tracer output, and sh run.

Please rate helpful posts

Best Regards,

Eugene

It seems like I was a little bit to quick here.

I thought that traffic passing between two sub-interrfaces on the same physical interface only needed the "same-security-traffic permit intra-interface" command but it seems like the ASA considers the sub-interfaces as being inter-interfaces to each other. So the command noted in Eugenes' post was correct!

Thanks!!!

Best Regards

Jhonny Eriksson

Review Cisco Networking for a $25 gift card