ASA Security Levels
With the IOS zoned-based firewall (ZBF) discussed in a previous chapter, we placed interfaces into zones, and no traffic was allowed between zones until we specified a policy.
With the ASA, it works a bit differently. The ASA uses security levels associated with each routable interface. The security level is a number between 0 and 100. The bigger the number, the more trust you have for the network that the interface is connected to. For example, I would very likely give a value of 100 to the interface that is connected to my inside network because it is the most trusted network I am connected to. Be aware, though, that we are not just talking about the directly connected network, but also any packets that might come in to ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access