<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD external access for anyconnect issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-external-access-for-anyconnect-issues/m-p/4080543#M1069919</link>
    <description>&lt;P&gt;I have setup Remote VPN on a Cisco ASA 5515-x running FTD.&amp;nbsp; I am unable to ping the external interface but i am able to ping out.&amp;nbsp; The NAT is setup correctly as i can tell.&amp;nbsp; i am also unable to ping the external interface.&amp;nbsp; I do see connection coming in as well on the capture. Below is what i have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT&lt;/P&gt;&lt;P&gt;object network any-ip&lt;BR /&gt;nat (inside,outside) static interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Capture&lt;/P&gt;&lt;P&gt;1: 14:29:54.773580 &lt;FONT color="#FF6600"&gt;&lt;EM&gt;&lt;STRONG&gt;X.X.X.X&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;.3736 &amp;gt; &lt;FONT color="#3366FF"&gt;&lt;EM&gt;&lt;STRONG&gt;Y.Y.Y.Y&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;.443: S 1041542606:1041542606(0) win 64240 &amp;lt;mss 1380,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: CAPTURE&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network any-ip&lt;BR /&gt;nat (inside,outside) static interface&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface inside&lt;BR /&gt;Untranslate &lt;FONT color="#3366FF"&gt;&lt;EM&gt;&lt;STRONG&gt;Y.Y.Y.Y&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;/443 to 0.0.0.0/443&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;access-group CSM_FW_ACL_ global&lt;BR /&gt;access-list CSM_FW_ACL_ advanced deny ip any any rule-id 268455992 event-log flow-start&lt;BR /&gt;access-list CSM_FW_ACL_ remark rule-id 268455992: ACCESS POLICY: usjgxxx-fw03 - Default&lt;BR /&gt;access-list CSM_FW_ACL_ remark rule-id 268455992: L4 RULE: DEFAULT ACTION RULE&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2020 14:44:49 GMT</pubDate>
    <dc:creator>tkraft</dc:creator>
    <dc:date>2020-05-06T14:44:49Z</dc:date>
    <item>
      <title>FTD external access for anyconnect issues</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-access-for-anyconnect-issues/m-p/4080543#M1069919</link>
      <description>&lt;P&gt;I have setup Remote VPN on a Cisco ASA 5515-x running FTD.&amp;nbsp; I am unable to ping the external interface but i am able to ping out.&amp;nbsp; The NAT is setup correctly as i can tell.&amp;nbsp; i am also unable to ping the external interface.&amp;nbsp; I do see connection coming in as well on the capture. Below is what i have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT&lt;/P&gt;&lt;P&gt;object network any-ip&lt;BR /&gt;nat (inside,outside) static interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Capture&lt;/P&gt;&lt;P&gt;1: 14:29:54.773580 &lt;FONT color="#FF6600"&gt;&lt;EM&gt;&lt;STRONG&gt;X.X.X.X&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;.3736 &amp;gt; &lt;FONT color="#3366FF"&gt;&lt;EM&gt;&lt;STRONG&gt;Y.Y.Y.Y&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;.443: S 1041542606:1041542606(0) win 64240 &amp;lt;mss 1380,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: CAPTURE&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network any-ip&lt;BR /&gt;nat (inside,outside) static interface&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface inside&lt;BR /&gt;Untranslate &lt;FONT color="#3366FF"&gt;&lt;EM&gt;&lt;STRONG&gt;Y.Y.Y.Y&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;/443 to 0.0.0.0/443&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;access-group CSM_FW_ACL_ global&lt;BR /&gt;access-list CSM_FW_ACL_ advanced deny ip any any rule-id 268455992 event-log flow-start&lt;BR /&gt;access-list CSM_FW_ACL_ remark rule-id 268455992: ACCESS POLICY: usjgxxx-fw03 - Default&lt;BR /&gt;access-list CSM_FW_ACL_ remark rule-id 268455992: L4 RULE: DEFAULT ACTION RULE&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 14:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-access-for-anyconnect-issues/m-p/4080543#M1069919</guid>
      <dc:creator>tkraft</dc:creator>
      <dc:date>2020-05-06T14:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD external access for anyconnect issues</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-access-for-anyconnect-issues/m-p/4080647#M1069920</link>
      <description>&lt;P&gt;It's unclear what you're trying to do.&lt;/P&gt;
&lt;P&gt;You talk about pinging but then present a packet capture for tcp/443.&lt;/P&gt;
&lt;P&gt;Could you explain the issue more clearly?&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 16:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-access-for-anyconnect-issues/m-p/4080647#M1069920</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-05-06T16:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTD external access for anyconnect issues</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-access-for-anyconnect-issues/m-p/4081293#M1069952</link>
      <description>&lt;P&gt;Pings to the External Interface of the ASA are controlled not with Access lists but the icmp permit command. Pings through the ASA are allowed with an ACL and a NAT&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 14:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-access-for-anyconnect-issues/m-p/4081293#M1069952</guid>
      <dc:creator>Michael ONeil</dc:creator>
      <dc:date>2020-05-07T14:39:00Z</dc:date>
    </item>
  </channel>
</rss>

