cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
616
Views
0
Helpful
3
Replies

Security level confusion !

Jonn cos
Level 4
Level 4

Hi all experts.

I am using ASA 8.0. Following is the simple topology

Pc1--------------------------ASA-------------------------------Pc2

      outside 0                         inside 100

Now what i have read that traffic from higher security level to lower security level is allowed. But when i ping from Pc2 to Pc1, it is not successfull. When i searched a bit more, i came to know that, i still need to apply access-list to allow traffic from 100 to 0.

Which point is correct ? do i explicitly need ACLs to permit traffic from higher level to lower level or is it allowed by default ?

1 Accepted Solution

Accepted Solutions

cadet alain
VIP Alumni
VIP Alumni

Hi,

the lower the security level the riskier it is and by default traffic can flow from high to low and return traffic is permitted in the reverse direction for TCP and UDP.

For ICMP you have 2 solutions to enable return traffic from low to high:

-enable ICMP inspection

- configure an ACL permitting echo replies and apply to outside interface inbound.

The first solution is the safest

the 2 ways are explained here: http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0

Regards.

Alain.

Don't forget to rate helpful posts.

View solution in original post

3 Replies 3

cadet alain
VIP Alumni
VIP Alumni

Hi,

the lower the security level the riskier it is and by default traffic can flow from high to low and return traffic is permitted in the reverse direction for TCP and UDP.

For ICMP you have 2 solutions to enable return traffic from low to high:

-enable ICMP inspection

- configure an ACL permitting echo replies and apply to outside interface inbound.

The first solution is the safest

the 2 ways are explained here: http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0

Regards.

Alain.

Don't forget to rate helpful posts.

Jonn cos
Level 4
Level 4

Ok i have understand why icmp didnt made through. Is there any debug command that can tell me which packet was dropped and why ??

Pls i need to make sure i am good with troubleshooting also. Pls guide me, what debug command will help me figure out why this icmp packets are being blocked.

Hi,

look at this doc:

http://www.cisco.com/en/US/docs/security/asa/asa83/asdm63/configuration_guide/admin_trouble.html

REgards.

Alain.

Don't forget to rate helpful posts.
Review Cisco Networking for a $25 gift card