cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
415
Views
0
Helpful
2
Replies

Default class inspection policy

mahesh18
Level 6
Level 6

Hi Everyone,

Need to know if default class inspection policy matches the incoming or outging traffic flowing through the ASA?

Example when i ping from PC  connecting to the ASA  to outside world will then it will match icmp traffic entering the ASA  then ICMP reply coming

to outside interface?

Thanks

MAhesh

1 Accepted Solution

Accepted Solutions

lcambron
Level 3
Level 3

Hello,

The ASA is stateful in both directions, so the policy matches incoming and outgoing traffic.

What happens is that you also have security levels, so from high to low it is allow but from low to high it will be deny unless you configure an ACL.

Regards,

Felipe.

View solution in original post

2 Replies 2

lcambron
Level 3
Level 3

Hello,

The ASA is stateful in both directions, so the policy matches incoming and outgoing traffic.

What happens is that you also have security levels, so from high to low it is allow but from low to high it will be deny unless you configure an ACL.

Regards,

Felipe.

Hi Felipe,

Many thanks for Prompt reply.

ASA is interesting world.

Regards

MAhesh

Review Cisco Networking for a $25 gift card