05-25-2016 06:35 AM - edited 03-12-2019 12:48 AM
Hi All,
can someone please explain how security levels work?
I know from lower to higher is not allowed and read that there is implicit deny on all lower level to higher level.
When I need to go from lower level to higher level , why would I apply the acl on lower level internal rather than higher level external?
If you have any documents that explains this in detail, it will be much appreciated.
Thanks
Aram
Solved! Go to Solution.
05-25-2016 07:26 AM
Hi,
The reason we need to apply the ACL on the lower security interface is because the traffic would hit the lower security interface first and then traverse the ASA engine.
You can check this link:
https://supportforums.cisco.com/discussion/11539041/asa-firewall-interface-security-levels-and-access-lists
Regards,
Aditya
Please rate helpful posts and mark correct answers.
05-25-2016 07:26 AM
Hi,
The reason we need to apply the ACL on the lower security interface is because the traffic would hit the lower security interface first and then traverse the ASA engine.
You can check this link:
https://supportforums.cisco.com/discussion/11539041/asa-firewall-interface-security-levels-and-access-lists
Regards,
Aditya
Please rate helpful posts and mark correct answers.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide