cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
349
Views
0
Helpful
3
Replies

same-security-traffic command queries

glenn.ong
Level 1
Level 1

Dear experts,

I wonder if putting in the "same-security-traffic permit intra-interface" or "same-security-traffic permit inter-interface" global commands will make the traffic 'bypass' the ACL for interfaces with same security level?

Your answer is much appreciated.

1 Accepted Solution

Accepted Solutions

Glenn

The short answer is yes if there is an access-list on the interface then there must be an entry allowing the traffic for it to be allowed back out.

For more details have a look at this document.

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml#t5

HTH

Jon

View solution in original post

3 Replies 3

Jon Marshall
Hall of Fame
Hall of Fame

Hi Glenn

The "same-security-traffic permit inter-interface" command will indeed allow traffic to flow between interfaces without access-lists.

The "same-security-traffic permit intra-interface" allows traffic to exit out on the interface it was received on.

Please see attached doc for more details.

http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1289167

HTH

Jon

Hi Jon,

Thanks for the speedy response.

For "same-security-traffic permit intra-interface" command, will the originating traffic that exits on the same interface still hit the access-list though?

One of our customers have their VPN and thirparty network coming in on the same interface on a FWSM - obviously for VPN-> third party connections, this command is needed to make it work but the connections have to be enforced by ACL too.

Glenn

The short answer is yes if there is an access-list on the interface then there must be an entry allowing the traffic for it to be allowed back out.

For more details have a look at this document.

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml#t5

HTH

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: