Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Cisco ASA 5505 Firewall - Trying to understand implicit rules

Posted on 2010-11-17
4
2,109 Views
Last Modified: 2012-05-10
A coworker created and later deleted the SMTP exception on the Cisco ASA 5505 firewall shown in the image.  I want to better understand the implicit setting that appears below the SMTP exception.  When he deleted the SMTP exception, it disappeared and the implicit rule disappeared as well.  Does the implicit rule still exist even though it isn't visible?
Implicit-Rule-on-ASA-5505.png
0
Comment
Question by:jdana
  • 2
  • 2
4 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 250 total points
ID: 34156518
The implicit deny can not be removed.  There is always an implicit "deny ip any any" at the bottom of an access-list.

What ASDM may have done is removed the access-list since you deleted the last rule in the list.
0
 

Assisted Solution

by:jdana
jdana earned 0 total points
ID: 34156957
JFrederick29,

If I understand you correctly, the implicit rule is still in effect even though it isn't visible?

J
0
 
LVL 43

Assisted Solution

by:JFrederick29
JFrederick29 earned 250 total points
ID: 34157023
As long as an acess-list is bound to the interface, yes.  If there is no access-list, the implicit nature of the Firewall takes place which is to allow all traffic from a higher security interface such as the inside interface to a lower security interface such as the outside.
0
 

Author Closing Comment

by:jdana
ID: 34216107
Thanks!
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco VPN client v5 migration to Anyconnect VPN? 8 52
Internet Connection -- PING testing ? 1 41
Cisco WRVS4400N 11 37
Upgrading from Sonicwall Tz210 6 12
I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question