7-7
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 7 Configuring Interface Parameters
Allowing Communication Between Interfaces on the Same Security Level
hostname/contextA(config-if)#
mac-address 030C.F142.4CDE standby 040C.F142.4CDE
hostname/contextA(config-if)#
no shutdown
Allowing Communication Between Interfaces on the Same
Security Level
By default, interfaces on the same security level cannot communicate with each other. Allowing
communication between same security interfaces provides the following benefits:
•
You can configure more than 101 communicating interfaces.
If you use different levels for each interface and do not assign any interfaces to the same security
level, you can configure only one interface per level (0 to 100).
•
You want traffic to flow freely between all same security interfaces without access lists.
Note
If you enable NAT control, you do not need to configure NAT between same security level interfaces.
See the
“NAT and Same Security Level Interfaces” section on page 17-13
for more information on NAT
and same security level interfaces.
If you enable same security interface communication, you can still configure interfaces at different
security levels as usual.
To enable interfaces on the same security level so that they can communicate with each other, enter the
following command:
hostname(config)#
same-security-traffic permit inter-interface
To disable this setting, use the
no
form of this command.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......