06-13-2013 08:48 PM - edited 03-11-2019 06:57 PM
Hi Everyone,
I read below line --
Implicit interface access rule that permits all IP traffic from high security level to low security level interface is disabled
automatically after the global access list has been defined and applied.
Need to know what does it mean?
I know global ACL applies to whole ASA,its for traffic for the ASA itself and is always in inward direction.
Regards
MAhesh
Solved! Go to Solution.
06-13-2013 08:50 PM
Hello Mahesh,
Exactly,
If global ACL it's applied to all of the interfaces in the IN direction, then the implicit rule of :
'All traffic from higher to lower security level will be lost"
Why?
Because u will be allowing now only what's permitted in the Global ACL
Regards
Remember to rate all of the helpful posts.
For this community that's as important as a thanks.
06-14-2013 08:45 AM
Hello Mahesh,
No, is not to the ASA only ( I mean it will filter data-plane and control plane traffic. Not just control-plane)
So it's traffic across and to the ASA,
Where did u hear it was to the ASA only?
Regards
Remember to rate all of the helpful posts.
For this community that's as important as a thanks.
06-13-2013 08:50 PM
Hello Mahesh,
Exactly,
If global ACL it's applied to all of the interfaces in the IN direction, then the implicit rule of :
'All traffic from higher to lower security level will be lost"
Why?
Because u will be allowing now only what's permitted in the Global ACL
Regards
Remember to rate all of the helpful posts.
For this community that's as important as a thanks.
06-14-2013 07:35 AM
Hi Julio,
But global ACL is for traffic to the ASA itself not passing through it.
ACL is for traffic passing through the ASA.
When you say 'All traffic from higher to lower security level will be lost" does this mean traffic passing through the ASA or traffic to the ASA itself?
Thanks
Mahesh
06-14-2013 08:45 AM
Hello Mahesh,
No, is not to the ASA only ( I mean it will filter data-plane and control plane traffic. Not just control-plane)
So it's traffic across and to the ASA,
Where did u hear it was to the ASA only?
Regards
Remember to rate all of the helpful posts.
For this community that's as important as a thanks.
06-14-2013 08:49 AM
Hi Julio,
May be i am wrong.
I will double check that and will update you.
Regards
Mahesh
06-14-2013 09:01 AM
Hello Mahesh,
Sure, take ur time,
Regards,
Remember to rate all of the helpful posts.
For this community that's as important as a thanks.
06-15-2013 04:30 PM
Hi Julio,,
You are right Sir.
i was confusing this with Management access rule in the ASDM.
I again listen my training videos and it confirmed that you are correct.
Regards
MAhesh
Message was edited by: mahesh parmar
06-15-2013 10:12 PM
Hello Mahesh,
My pleasure to help,
What training videos are you studying?
Regards
Remember to rate all of the helpful posts.
For this community that's as important as a thanks.
06-15-2013 10:21 PM
Hi Julio,
CBT Security CCNP --ASA.
They are really good and helping me out to understand the ASA.
Regards
MAhesh
06-16-2013 10:59 AM
Hello Mahesh,
Amazing, keep the hard work
Remember to rate all of the helpful posts.
For this community that's as important as a thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide