Solved

ASA EGRESS AND INGRESS

Posted on 2012-03-31
1
1,620 Views
Last Modified: 2012-06-27
Experts,

Assume I have an ASA 5510 with a very basic setup.

int e0/0 is the outside interface that is connected to the internet.
int e0/1 is the inside interface.

Now, computer 10.10.10.10 from the inside network browses the internet 4.4.4.4.

question 1: When I run a packet capture on this; is the inside interface the INGRESS interface and the outside interface the EGRESS interface?

question 2: If I want to see the return traffic coming back to 10.10.10.10 from 4.4.4.4, would I still look at the ingress capture? It looks like when you run a packet capture and specify an interface for ingress it automatically shows outbound and inbound traffic on that interface. Is that correct?
0
Comment
Question by:trojan81
1 Comment
 
LVL 17

Accepted Solution

by:
Kvistofta earned 500 total points
ID: 37793696
1) Yes. Ingress means inbound. Since the packet is coming IN TO the firewall from the inside interface, that is the ingress. The packet is going OUT FROM the outside interface, therefore it is the egress (outbound) interface.

2) When you capture packets on an interface, you see ALL packets, both ingress packets (packets entering the firewall on that interface) AND egress packets (packets leaving the firewall).

Best regards
Kvistofta
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Join & Write a Comment

How to configure Site to Site VPN on a Cisco ASA.     (version: 1.1 - updated August 6, 2009) Index          [Preface]   1.    [Introduction]   2.    [The situation]   3.    [Getting started]   4.    [Interesting traffic]   5.    [NAT0]   6.…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now