FirewallWizards
[Top] [All Lists]

[fw-wiz] New to Cisco PIX/ ASA

To: <firewall-wizards@listserv.icsalabs.com>
Subject: [fw-wiz] New to Cisco PIX/ ASA
From: "Keith A. Glass" <salgak@speakeasy.net>
Date: Wed, 1 Aug 2007 18:41:53 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
Thread-index: AcfUjOFkkdFsQEmKTcGlBSS38fnuNQ==

I’ve managed Gauntlets, Checkpoints, Netscreens, and SonicWalls in the past.

 

I’m a bit confused with the in and outs of the ASA firewalls.

 

I’m setting up at HA pair, my Eth0/0 is my interior interface, trust level 100, Eth 0/1 and 0/2 are my IP and State heatbeats, and Eth 1/0 is my external interface, trust level 1.

 

Am I correct in my understanding that if I want two-way traffic, traffic is not blocked to a lower trust level, so I need only write a rule to pass the traffic between the endpoints from the external interface to the internal interface, and the reply traffic is taken care of ??  Or do I have to write a reverse rule, from the internal interface to the external as well ???

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
<Prev in Thread] Current Thread [Next in Thread>
  • [fw-wiz] New to Cisco PIX/ ASA, Keith A. Glass <=