cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
354
Views
5
Helpful
1
Replies

On ASA5525 with vanilla setup, need to place ACL on outside int?

Hi.

On an ASA5525 within a vanilla configuration, because of default "0, 50, 100" security levels, and also because default is "sysopt connection permit-vpn",

Is there a general need to place any ACL on the outside interface?

Thank you.

1 Accepted Solution

Accepted Solutions

@jmaxwellUSAF No. The outside interface would as default have a security level of 0, the inside interface with a security level of 100, traffic from lower security level (0) to higher (100) would, by default be denied. You only need an ACL inbound on the outside interface if you wish to selectively permit traffic.

"sysopt connection permit-vpn" is applicable to ignoring the interface ACL for encrypted traffic (L2L or RAVPN).

View solution in original post

1 Reply 1

@jmaxwellUSAF No. The outside interface would as default have a security level of 0, the inside interface with a security level of 100, traffic from lower security level (0) to higher (100) would, by default be denied. You only need an ACL inbound on the outside interface if you wish to selectively permit traffic.

"sysopt connection permit-vpn" is applicable to ignoring the interface ACL for encrypted traffic (L2L or RAVPN).

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card