<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Passing Layer 3 Traffic Through Transparent Mode FTDv in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3318171#M1064520</link>
    <description>&lt;P&gt;I have a rule&amp;nbsp;to permit any any&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jan 2018 02:53:01 GMT</pubDate>
    <dc:creator>Dia</dc:creator>
    <dc:date>2018-01-25T02:53:01Z</dc:date>
    <item>
      <title>Passing Layer 3 Traffic Through Transparent Mode FTDv</title>
      <link>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3318117#M1064516</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am doing a new deployment of Virtual Firepower Thread Defense (FTDv) using ESXI and using ACI as bridge domain for my infrastructure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My problem is the FTDv is running in Transparent mode between 2 routers and these routers will be running IBGP over different links one of them having the FTDv inline, BGP is not forming over this link so any Idea what could be the reason?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3318117#M1064516</guid>
      <dc:creator>Dia</dc:creator>
      <dc:date>2020-02-21T15:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Passing Layer 3 Traffic Through Transparent Mode FTDv</title>
      <link>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3318160#M1064518</link>
      <description>&lt;P&gt;BGP requires TCP port 179 to be open between peers. check on your FW to see if this is allowed&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 02:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3318160#M1064518</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-01-25T02:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Passing Layer 3 Traffic Through Transparent Mode FTDv</title>
      <link>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3318171#M1064520</link>
      <description>&lt;P&gt;I have a rule&amp;nbsp;to permit any any&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 02:53:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3318171#M1064520</guid>
      <dc:creator>Dia</dc:creator>
      <dc:date>2018-01-25T02:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Passing Layer 3 Traffic Through Transparent Mode FTDv</title>
      <link>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3318277#M1064522</link>
      <description>&lt;P&gt;Are you using BGP-authentication? Then you need a workaround:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuy10017" target="_self"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuy10017&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 07:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3318277#M1064522</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2018-01-25T07:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Passing Layer 3 Traffic Through Transparent Mode FTDv</title>
      <link>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3320578#M1064524</link>
      <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your feedback that would help in later stage bu actually i am in the stage to establish the BGP without authentication&amp;nbsp;&lt;SPAN&gt;between two BGP speaking routers peering with each other and no BGP running on FTD as it is Transparent.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2018 22:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3320578#M1064524</guid>
      <dc:creator>Dia</dc:creator>
      <dc:date>2018-01-28T22:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Passing Layer 3 Traffic Through Transparent Mode FTDv</title>
      <link>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3347092#M1064525</link>
      <description>&lt;P&gt;In transparent mode of Firewall, you needs to create bridge groups to the vlans at both (in/out) side of firewall.&lt;BR /&gt; &lt;BR /&gt; Example: Configuration on Inside/outside interfaces:&lt;BR /&gt; &lt;BR /&gt; interface TenGigabitEthernet0/6&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp; vlan 20&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp; nameif inside&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp; bridge-group 1&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp; security-level 100&lt;BR /&gt; &lt;BR /&gt; interface TenGigabitEthernet0/7&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp; vlan 30&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp; nameif outside&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp; bridge-group 1&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp; security-level 0&lt;BR /&gt; &lt;BR /&gt; Now please configure "BVI" interface with one IP from the same IP Subnet for which you want to pass traffic through firewall:&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt; interface BVI1&lt;BR /&gt; &lt;BR /&gt; ip address 192.168.10.9 255.255.255.0 standby 192.168.10.10&amp;nbsp; (any free IP can be assigned from subnet)&lt;BR /&gt; &lt;BR /&gt; Now, please allow interested traffic on ouside Interface via access-list. This will redirect traffic through transparent firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 20:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3347092#M1064525</guid>
      <dc:creator>sbhadrav@cisco.com</dc:creator>
      <dc:date>2018-03-12T20:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Passing Layer 3 Traffic Through Transparent Mode FTDv</title>
      <link>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3347349#M1064526</link>
      <description>&lt;P&gt;Hi Dia,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest you change the firewal mode to routed from transparent.&lt;/P&gt;
&lt;P&gt;Transparent is more of a headache. You can have the same inline processing of traffic using routed mode with inline pairs, without any need for a BVI interface with IP and so on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Afterwards, you can create your own rules to permit TCP 179 between peers plus TCP option 19 for BGP authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 08:17:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-layer-3-traffic-through-transparent-mode-ftdv/m-p/3347349#M1064526</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2018-03-13T08:17:21Z</dc:date>
    </item>
  </channel>
</rss>

