issue of same-security-traffic

ASA5505 config

IP address inside 10.1.1.254 255.255.255.0

NAT (inside) 1 10.1.1.0 255.255.255.0

Route inside 10.1.2.0 255.255.255.0 10.1.1.253

permit same-security-traffic intra-interface

When I source packets from 10.1.1.1 host I can't reach 10.1.2.1 host

default gateway on 10.1.1.1 is 10.1.1.254

If I "route add 10.1.2.0 mask 255.255.255.0 10.1.1.253" to 10.1.1.1 host I can then reach 10.1.2.1 host

What I'm missing here? Everything else I have to do the work.

THX,

Phil

That should make it work.

Global (inside) 1 interface

Tags: Cisco Security

Similar Questions

  • ASA - same-security-traffic allowed inter VS permit/deny access-list interface

    Hi people,

    I wonder if I use the same-security-traffic permits inter-interface order to ASA and I have 2 separate interfaces with the same level of security and ACL with a few rules explicit allow , if not covered by these statements to allow traffic will be blocked by implicit deny at the end of the ACL or am I completely wrong in my thinking?

    That is right.

    But then if you have an interface with an ACL and another interface without an ACL and you want to pass traffic between the two interfaces, then the interface without an ACL will rely on the level of security while configured with the ACL interface will rely on configured ACL entries.

    --

    Please do not forget to select a correct answer and rate useful posts

  • queries of the same-security-traffic command

    Dear experts,

    I wonder if put in the "same-security-traffic intra-interface permits" or blanket orders 'same-security-traffic licence inter-interface' will make the traffic to "bypass" the ACL for the interfaces with the same level of security?

    Your response is much appreciated.

    Glenn

    The short answer is Yes if there is an access to the interface list then there must be an entry allowing traffic to be allowed back.

    For more details, take a look at this document.

    http://www.Cisco.com/en/us/products/ps6120/products_tech_note09186a0080734db7.shtml#T5

    HTH

    Jon

  • Repeated downloads (much, much) the same security update.

    A security update for Microsoft XML Core Services 4.0 Service Pack 2 (KB954450)
    This point was first downloaded to my system on 23 July 09.  Since then, to date (Oct 06) it has been downloaded and installed auto that I close my system at the end of the day 97 times!  I'm under Vista Home Premium on a laptop and every time I leave on stand-by, I can't because this update is waiting to be downloaded and automatically turns the unit off when you are finished.  The situation is completely unacceptable, but I don't see what I can do to avoid it.  Can someone please provide a response?   Thanks in advance.

    A security update for Microsoft XML Core Services 4.0 Service Pack 2 (KB954450)
    This point was first downloaded to my system on 23 July 09.  Since then, to date (Oct 06) it has been downloaded and installed auto that I close my system at the end of the day 97 times!   I'm under Vista Home Premium on a laptop and every time I leave on stand-by, I can't because this update is waiting to be downloaded and automatically turns the unit off when you are finished.  The situation is completely unacceptable, but I don't see what I can do to avoid it.  Can someone please provide a response?   Thanks in advance.

    A security update for Microsoft XML Core Services 4.0 Service Pack 2 (KB954430 ) are you referring to?
    There is no KB954450. If so, then see known issues with this security update of the Ko.
    The reason why the update is offered several times is that is not install properly because the msxml being locked files / in use or there is a problem with corruption of files.
    If the first is the origin of the problem, suggest you clean boot Vista , and then install the update. Use step 1: perform a clean boot . Cancel the clean boot using the step 7: reset the computer to start as usual .

    If the latter is the origin of the problem then suggest you see:
    For Microsoft XML Core Services 4.0 Service Pack 2 security updates may repeatedly appear in the update on Microsoft Update or Windows Update list

    You can also uninstall MSXML 4 SP2, reboot and uninstall any other 4 MSXML listed in programs and features. MSXML 4 is not included in Vista, so it was most likely installed by 3rd party software that requires to work properly.
    Then download, Save and install MSXML 4.0 Service Pack 3 (Microsoft XML Core Services) .

    MowGreen MVP Data Center Management - update of safety Consumer Services

  • Update of same security, KB2538242, installs whenever I shut down.

    Since June 15, whenever I try to close the same security update is installed on my ProBook 4520 s running Windows 7 Pro. Any suggestions on how to fix this?

    Hello

    If the update is displayed as installed in the view installed updates, click check for updates again.  Click on the number of updates available to view individually, right-click the update of 2005 and select "Hide update".  This should prevent offered in the future.

    Kind regards

    DP - K

  • Cannot reset Apple ID same security issues with the link for valid reset. Help?

    So, I'm trying to reset my security questions, because I forgot the answers. I followed all the procedures to do, but it won't work.

    I clicked on the link for reset enter my Apple ID account page, then get the message: 'Reset Instructions sent. An email with the instructions was sent to @emailaddress. Follow the instructions in the email to reset your security questions. » - OK

    I opened the email: "Dear ME, recently made you a request to reset your Apple ID security questions and answers. To complete the process, click on the link below. Reset now >"I click on the link, it opens a new window with a login screen. - OK

    On the login screen, I entered my account information, email, and password in the fields and click the button to continue. Instead of connect, I get the message pop-under from the password field as follows: - FAIL

    I try again and again, but it never works. Whenever I get my password and trying to proceed, the loading spinner runs for a bit, then I get this message "to reset your security questions, sign in to your account and start again." I have never spent this page and in a region where I am able to actually reset my security questions. I tried with all browsers, Firefox, Chrome, Safari... nothing works. Now, I have tried 3 times reset by e-mail. It will not work. What is going on? Is the site broken?

    To make things worse, I don't have an option to call for framing according to the Apple website. The only option I get is to contact my operator. What the * is my carrier will repair my Apple ID? It's very frustrating say the least. Someone please help!

    You cannot reset the Security Questions If you forgot the. You can only reset them if you know them (which means that you also know your password).

    You can contact the Apple Support here to have a reset link you sent once they verify your identity:

    ACCOUNT SECURITY SUPPORT

    Good luck

    GB

  • Forget the security issue, forget answare security question whitout rescue by email

    I forgot my security question answare

    I buy the $ 15 gift card to make purchases on App Store and I didn't know what he answare security issue.

    As I'm living in iran, and I have no life-saving station, I don't know what I have to do

    I am pleased to help me

    Contact Apple security - Apple Support -  Contact security

    If your identifier Apple is locked - Apple supports

    Reset your Apple security questions - Apple Support

    iTunes_Contact_Form

  • Closing a tab gives the same security that close a browser?

    Before the arrival of the tabs, we have been invited to close the browser and open a new after being on a site that has involved sensitive information.

    Closing a tab in Firefox gives the same level of security, or should I continue to close the entire browser?

    No, who does not have the same protection. Some data may be revoked by closing and restarting Firefox, but even so, you still have the data stored on the disk in the cache or cookies even if you closed all tabs open before closing Firefox.

    You can switch to private browsing to prevent storage of the data at all, or you can use clear history recent to clear the last hour or more if necessary.

    Firefox 4 and later versions Save the previous session automatically, so it is no longer need for the dialog box asking if you want to save the current session.

    Use ' file > leave ' or ' Firefox > Exit ' (Mac: ' Firefox > quit Firefox ") If you want to restore multiple windows or have problems with the restoration of the tabs.

    You can use ' history > restore previous Session ' to get the previous session at any time.

    There is also a button 'Restore previous Session' on the default on: Home home page.

  • Vista will not stop the same security update. I install the update, and it immediately appears again.

    This is a security update. It's boring and afraid, that it slows down my PC.

    Hi Larry, thanks for your info

    Refer to this post that addresses a similar issue and follow the suggestion given by Kosh Vorlon - a regular contributor here.

    http://answers.Microsoft.com/en-us/Windows/Forum/windows_other-windows_update/kb2538242-this-particular-update-is-installed/794fe18f-4F65-404A-8361-68c6d6ef6a22>

    `~`

    Visit the Microsoft Solution Center and antivirus security for resources and tools to keep your PC safe and healthy.  If you have problems with the installation of the update itself, visit the Microsoft Update Support for resources and tools to keep your PC updated with the latest updates.

    For enterprise customers, support for security updates is available through your usual support contacts.

    `~`

    How to hide an update in Windows 7

    A. click the Start button, click principally made programs, and then click Windows Update.

    (B) in the left pane, click check for update.

    C. after receiving the results of the analysis, please click to see the available updates under the install updates button.

    D. Please right- click the update (KB2538242), and then click hide update.

    `~`

    Refer to this post that addresses a similar issue and follow the suggestion given by Kosh Vorlon - a regular contributor here.

    http://answers.Microsoft.com/en-us/Windows/Forum/windows_other-windows_update/kb2538242-this-particular-update-is-installed/794fe18f-4F65-404A-8361-68c6d6ef6a22>

    07/01 / 1102:47: 23:00

  • Security issues with Microsoft Security essential and other anti-malware, anti-spyware programs

    Hello, I would like you to help mewith the following questions...

    Related to the question of the conflict between the programs microsoft security essential antivirus and antimalware bytes free (anti-malware) what is your opinion? Can they work together?
    And a second question: can I have windows firewall turned on at the same time with another protection in real time from the anti-malware bytes and Super anti-spyware free software?
    And the last question: what Windows Defender?
    I disabled it in my computer, probably because I use Mr. S. Essential, is necessary in the 32-bit edition of Vista business with MSE and Antimalware running together?
    Thnx in advance...

    Free Malwarebytes and Superantispyware Free cause no conflict with Microsoft Security Essentials.

    Keep Windows Firewall turned on.
    You can't and don't need to use Windows Defender on Vista, when you use Microsoft Security Essentials.

    You can find the answers to these questions and others like it in the FAQ Guide reference Microsoft Security Essentials
  • Design of authentication issues and wireless security

    Wireless newbie here... I had to quicky throws a wireless deployment in a new office/warehouse building. I have the basic net upward and the work. My remote access point associated the 2106 in the main office and users can associate and authenticate to the AP 1130 G and can access the office network. I did the basic configs and now seeks to tighten security. My questions are the following:

    (1) the user clients are Dell laptops with built-in radio. They authenticate using JUMP... How to migrate to EAP or I have to. I have a Cisco ACS as RADIUS authentication.

    (2) can I use sort of a supplicant client on laptops?

    (3) how to filter mac while rogue AP and clients of thugs can not try and associate.

    (4) am I correct in assuming the connections between the AP 1130 and 2106 are secure and if so what I need to change anything to strengthen them?

    (5) I have an AP in the main building, I want Setup to detect rogue AP I associate him as a regular access point and push a kind of policy so that it becomes a detector?

    I have attached a diagram to explain. Any help would be appreciated.

    v/r

    Chad

    1 JUMP is a form of EAP, so you already have something to terminate your EAP sessions. The WLC can do to an extent, or ACS. We chose you will be based on your needs for the rich functionality, scalability, and manageability. I would say that PEAP-MSCHAPv2 offers a good compromise between ease of use and safety and that it is significantly better than LEAP.

    2 No, begging stick with Windows XP SP2. This can be configured by using the domain policy (2 k 3 SP1 or higher) and is pretty good. Just make sure that your laptops have new Intel drivers on them. Dell in particular have been pretty bad with sends former pilots in the builds.

    3 MAC authentication is now lergely, considered to be a waste of time. It's so easy to spoof a MAC address, it is ridiculous, and there is a fair amount of work for the privΘ.

    4. the tunnel LWAPP crypt all management / config / traffic safety between the AP and WLC, while user data are simply wrapped in LWAPP, so it can potentially be read if the packets are captured.

    5. any will to detecting rogue APs, must really dedicated APs unless you are REALLY paranoid. The major advantage is the fastest detection, but the downside is that the "detector" AP do service customers.

    Kind regards

    Richard

  • Where to find Flex SDK (Flex Security Issue APSB11-25) security patches?

    On the Flex Security Issue APSB11-25page, link to the patch (https://helpx.adobe.com/content/dam/kb/en/915/cpsid_91544/attachments/APSB11_25_Patch_Tool .air) tool does not work but gives error 404. Where can I find the tool?

    I found the tool patch here: http://kb2.adobe.com/cps/915/cpsid_91544/attachments/APSB11_25_Patch_Tool.air

  • 4.6 Server issues matching connection security

    Hi all

    We use 4.6.

    Is the only way to associate a server with another server of connection security for uninstall security server software, remove the Console from the administrator of the view security server, and then reinstall specifying the desired login server?

    Is it possible for two security servers to be paired with the same login server at the same time?  Thinking through what I do, maybe I need to have this scenario for a little while.

    Finally, if I want clients that connect through one of my servers to connect to establish their sessions RDP and PCoIP directly with the Office of the VDI, after authentication, etc., do I just need to uncheck the boxes on the configuration of this server connection who say "Secure usage on the desktop connection Tunnel" and "Use Secure Gateway of PCoIP PCoIP connections to desktop"?

    Thanks for any help!

    Steve

    The Security server is matched during the installation process if you need to reinstall in order to re pair the SS with a broker for connections.  You can also have several SS paired with a single connection broker.

    Yes, unchecking the boxes would cause a direct connection.

    http://KB.VMware.com/kb/1010795

  • Issue of non-secure/SSL in 14.0.1

    Looks like there may be a problem with FF 14.0.1 caching. If you visit any site safely... we will say "https://support.mozilla.org" and you close your browser and reopen and type 'http://support.mozilla.org' or 'support.mozilla.org', you get automatically meant the secure version of the site. This isn't a redirect on the side server, it seems that the browser is cached you once accessed the area firmly and now every time you visit what you want to do. No other browser I've tried behaves like that for all the Web sites that we operate. This creates problems in several areas of our sites because some areas were supposed to be consulted not securely. I understand that a well-designed site would be capable of supporting access via a protocol throughout each part of a Web site. However, we have many sites and many were scheduled long ago and just updated across all revisions, update each of them would be so much of your time.

    So my question is... are others perceiving this caching behavior? Is it planned? Is this a bug?

    Hi barth.shawn, you could use the redirection server displayed in the first link above, as appropriate.

  • Issue of Microsoft Security Center

    Running Windows7 Home Prem 64 bit...

    Action Center displays an alert;

    Windows Security Center service (Important) turn ON NOW

    When I click on tour now I get... .it cannot be started.  When I develop the alert I see bed that UAC will notify when programs try to make changes to the computer on and OFF Network Access Protection.

    I went to the 'Services '... Security Center service is not in the list...

    How can I remove this alert in the center of the Action?

    Hey,.

    check the suggestions of Ramesh.

    http://answers.Microsoft.com/en-us/Windows/Forum/Windows_7-Security/Windows-Security-Center-service-has-been-removed/47b55525-f0be-4434-95c3-265fbba64807

Maybe you are looking for

  • iPhone Unlocked 6s more LTE support

    I've had an iPhone more than 6 s and I would like to know the iPhone works with all phone services and how can I tell her work with sprint and verzion?

  • Re: Satellite C660 - need software for keys FN for XP

    I bought the laptop Toshiba Satellite C660-a9k.I found all the drivers & configure Windows XP SP3. Can't find the FN keys software support for this model for XP.I tried common module + controls C650. It does not work.There is no package of added valu

  • Unable to load dynamic library

    Does this mean I'm screwed?

  • Google Chrome OS

    need to download Photosmart software 5520 on my hp Pavilion Chromebook, no dvd drive, how can I do?

  • Cannot Auto-Detect Simulator.

    I'm frustrated by the development of BB10 because the controller and IDE is unable to automatically detect the simualtor. What can I do to solve this problem -Adil