Vito_Corleone wrote:
zerojunkie wrote:
Unfortunately, iirc, the security-level business goes out the window once you apply an ACL to the interface. That's not the case with most other ZBFs I've tried.
Explain. I haven't used ZBF much at all, but I don't see how you could add an access rule and still have trust levels matter. Would you want a permit (or deny) ip any to be overridden by a default lower to higher/higher to lower rule?
Funny enough I came across this type of discussion in the cisco forms the other day where some guy was saying the complete opposite...I was like wtf?

Granted it was from '10 and had popped up in a search I was doing
Quote:
Re: ASA / Same-security interface filtering with ACLs
Hello,
The same security traffic will override any ACL that you have apply on the interfaces with the same security. If you take a look at the ASDM says "Permit traffic to flow between same security interfaces". No ACL can override this rule.
Hope it helps.
Mike
He then goes on to say
Quote:
Hello,
Also to back me up over here, you can find the information here
"You can allow traffic to flow freely between all same security interfaces without access lists"
http://www.cisco.com/en/US/docs/securit ... #wp1289167 Since the same security traffic is checked prior an ACL, if this command is present, all the traffic will be allowed. If you want to do filtering, I would suggest you to take out the command and put the ACL's in all of the interfaces.
Cheers
Mike