Allowing Communication Between Vlan Interfaces On The Same Security Level - Cisco FirePOWER ASA 5500 series Configuration Manual

Security appliance command line
Hide thumbs Also See for FirePOWER ASA 5500 series:
Table of Contents

Advertisement

Chapter 4
Configuring Switch Ports and VLAN Interfaces for the Cisco ASA 5505 Adaptive Security Appliance
hostname(config-if)# interface ethernet 0/1
hostname(config-if)# switchport mode trunk
hostname(config-if)# switchport trunk allowed vlan 200 300
hostname(config-if)# no shutdown
Allowing Communication Between VLAN Interfaces on the
Same Security Level
By default, interfaces on the same security level cannot communicate with each other. Allowing
communication between same security interfaces lets traffic flow freely between all same security
interfaces without access lists.
If you enable NAT control, you do not need to configure NAT between same security level interfaces.
Note
See the
and same security level interfaces.
If you enable same security interface communication, you can still configure interfaces at different
security levels as usual.
To enable interfaces on the same security level so that they can communicate with each other, enter the
following command:
hostname(config)# same-security-traffic permit inter-interface
To disable this setting, use the no form of this command.
OL-10088-01
"NAT and Same Security Level Interfaces" section on page 17-12

Allowing Communication Between VLAN Interfaces on the Same Security Level

Cisco Security Appliance Command Line Configuration Guide
for more information on NAT
4-13

Advertisement

Table of Contents
loading

This manual is also suitable for:

Pix 500 seriesCisco asa 5500 series

Table of Contents