Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Some Questions about ASA-System

Status
Not open for further replies.

xyCruiseryx

Technical User
Oct 18, 2004
94
DE
HI,

i have some probs bto understand the ASA-System

I configured 2 Zones:

Zone A (incoming) SecurityLevel with 100%


Zone B (incoming) SecurityLevel with 50%

If i establish a connection from ZoneA to ZoneB, the ASA will not take a look in the own Policytabel cause the Zone A with 100% is higher than the Zone B with 50%.Is that right that all traffic from ZoneA can flow in overall Zones with a lower Security as 100%?

Do i need a way back from ZoneB in ZoneA if the connection ist start from ZoneA? Or is the connection saved in the Sessiontable as log as the traffic will flow?


UDP:

How will handel the ASA UDP traffic between the two zones? Will the ASA hold the session too in the sessiontable if my connecton is only using UDP?


Many Thanks,
 
ASA will hold a UDP connection entry in its table. The security levels are correct although its not percentages.

the higher security level will always have entry into lower levels unless an acl is applied to the higher security level interface.

To work back the other way you will need an access-list entry and a translation like static or nat 0.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top