Re: [c-nsp] IPv6 firewall rules/inspection on ASAs

2012-09-13 Thread Justin M. Streiner
On Thu, 13 Sep 2012, Joseph Jackson wrote: Silly question - How come you are having to deny certain things, if traffic from a lower security interface tries to access a higher security interface unless its permit it should be denied by default. Are you putting those deny statements in there jus

Re: [c-nsp] IPv6 firewall rules/inspection on ASAs

2012-09-13 Thread Joseph Jackson
Silly question - How come you are having to deny certain things, if traffic from a lower security interface tries to access a higher security interface unless its permit it should be denied by default. Are you putting those deny statements in there just to log the hits? Also notice there is a deny

Re: [c-nsp] IPv6 firewall rules/inspection on ASAs

2012-09-13 Thread Justin M. Streiner
On Wed, 12 Sep 2012, Justin M. Streiner wrote: A number of people have asked to see the ruleset, so I've posted it here: http://www.cluebyfour.org/ipv6/ What I've posted is the IPv6 portion of the configuration for my test zone. I see a number of people have viewed the config since I posted

Re: [c-nsp] IPv6 firewall rules/inspection on ASAs

2012-09-11 Thread Justin M. Streiner
A number of people have asked to see the ruleset, so I've posted it here: http://www.cluebyfour.org/ipv6/ What I've posted is the IPv6 portion of the configuration for my test zone. jms On Fri, 7 Sep 2012, Justin M. Streiner wrote: This is as much of a general query as anything else. I'm j

[c-nsp] IPv6 firewall rules/inspection on ASAs

2012-09-07 Thread Justin M. Streiner
This is as much of a general query as anything else. I'm just trying to get a sense for how people are building default firewall rule sets on their ASAs. I have a fairly detailed inbound and outbound default IPv6 firewall rule set worked up, which I can share with people who are interested. S