Allowing Communication Between Interfaces On The Same Security Level - Cisco FirePOWER ASA 5500 series Configuration Manual

Security appliance command line
Hide thumbs Also See for FirePOWER ASA 5500 series:
Table of Contents

Advertisement

Allowing Communication Between Interfaces on the Same Security Level

Allowing Communication Between Interfaces on the Same
Security Level
By default, interfaces on the same security level cannot communicate with each other. Allowing
communication between same security interfaces provides the following benefits:
Note
If you enable NAT control, you do not need to configure NAT between same security level interfaces.
See the
and same security level interfaces.
If you enable same security interface communication, you can still configure interfaces at different
security levels as usual.
To enable interfaces on the same security level so that they can communicate with each other, enter the
following command:
hostname(config)# same-security-traffic permit inter-interface
To disable this setting, use the no form of this command.
Cisco Security Appliance Command Line Configuration Guide
7-6
You can configure more than 101 communicating interfaces.
If you use different levels for each interface and do not assign any interfaces to the same security
level, you can configure only one interface per level (0 to 100).
You want traffic to flow freely between all same security interfaces without access lists.
"NAT and Same Security Level Interfaces" section on page 17-12
Chapter 7
Configuring Interface Parameters
for more information on NAT
OL-10088-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Pix 500 seriesCisco asa 5500 series

Table of Contents