[fw-wiz] New to Cisco PIX/ ASA



I've managed Gauntlets, Checkpoints, Netscreens, and SonicWalls in the past.



I'm a bit confused with the in and outs of the ASA firewalls.



I'm setting up at HA pair, my Eth0/0 is my interior interface, trust level
100, Eth 0/1 and 0/2 are my IP and State heatbeats, and Eth 1/0 is my
external interface, trust level 1.



Am I correct in my understanding that if I want two-way traffic, traffic is
not blocked to a lower trust level, so I need only write a rule to pass the
traffic between the endpoints from the external interface to the internal
interface, and the reply traffic is taken care of ?? Or do I have to write
a reverse rule, from the internal interface to the external as well ???

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Relevant Pages

  • Editing Windows firewall ruleset for 2003 Std ?
    ... I have an application that sends http request packets to a microsoft ... sent out via the main interface on 172.31.1.2. ... This works perfectly until I turn on the windows firewall. ... sending them out through the external interface. ...
    (comp.security.firewalls)
  • Editing Windows firewall ruleset for 2003 Std ?
    ... I have an application that sends http request packets to a microsoft ... sent out via the main interface on 172.31.1.2. ... This works perfectly until I turn on the windows firewall. ... sending them out through the external interface. ...
    (microsoft.public.security)
  • Editing Windows firewall ruleset for 2003 Std ?
    ... sent out via the main interface on 172.31.1.2. ... This works perfectly until I turn on the windows firewall. ... configured both the loopback and external interface to accept ... sending them out through the external interface. ...
    (microsoft.public.windows.server.networking)
  • rdr not working
    ... one for the internal network and one for the dmz ... see that the traffic is passed in through the external interface, ... not getting to the dmz interface. ...
    (comp.unix.bsd.openbsd.misc)
  • Re: ISA2004 - multiple external interfaces
    ... but Windows2003 is a router. ... traffic just trying to let traffic coming in on one interface stay on that ... When looking at the listener config it allows for configuration ... > single external interface out of the ...
    (microsoft.public.isa)