<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FMC/FTD - RAVPN - Need to route specific IPs via RAVPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4112263#M1071633</link>
    <description>&lt;P&gt;Hi Rob,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately its not working. I can see the traffic is being routed via the firewall successfully, but the service is not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To give you a little insight into what im trying to achieve - (&lt;EM&gt;attached a small drawing of the main components being used, just something i did in paint&lt;/EM&gt;)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have Microsoft SFB Federation services enabled between sip.local.com &amp;amp; sip.remote.com&lt;/LI&gt;&lt;LI&gt;Everything (&lt;EM&gt;including IM, Calls, Content sharing&lt;/EM&gt;) works between My Local LAN &amp;amp; Remote Site&lt;/LI&gt;&lt;LI&gt;Everything (&lt;EM&gt;including IM, Calls, Content sharing&lt;/EM&gt;) works between external users &amp;amp; Remote Site (&lt;EM&gt;i.e. since the SFB services are published outside, anyone in the internet can login to SFB &amp;amp; work&lt;/EM&gt;)&lt;/LI&gt;&lt;LI&gt;Only IM works between My VPN Users &amp;amp; Remote Site&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Calls &amp;amp; Content sharing fails&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;U&gt;My observations&lt;/U&gt; -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remote site have enabled federation services to sip.local.com&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This URL is NATted to our Edge DMZ&lt;/LI&gt;&lt;LI&gt;This Edge DMZ then has all the relevant routes to my local network &amp;amp; my vpn network&lt;/LI&gt;&lt;LI&gt;Hence, as far as local SFB Edge is concerned, it has successful routes to both (&lt;EM&gt;local &amp;amp; vpn&lt;/EM&gt;) network&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I tried to telnet sip.remote.com on port 5061 - the response is as below&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;My Local LAN - it works fine&lt;/LI&gt;&lt;LI&gt;Open internet from home (&lt;EM&gt;without VPN&lt;/EM&gt;) - it works fine&lt;/LI&gt;&lt;LI&gt;VPN connected - it does not work&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So as far as Remote Site is concerned, they are receiving the traffic successfully&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;i.e. if it comes from my Local Subnet, everything works fine.&lt;/LI&gt;&lt;LI&gt;but if it comes from my VPN Subnet, the routing issues comes into play&lt;UL&gt;&lt;LI&gt;Im suspecting there is no reverse route from Remote Site to my VPN subnet&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Is my understanding correct???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shabeeb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jul 2020 06:22:33 GMT</pubDate>
    <dc:creator>shabeeb</dc:creator>
    <dc:date>2020-07-02T06:22:33Z</dc:date>
    <item>
      <title>Cisco FMC/FTD - RAVPN - Need to route specific IPs via RAVPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4110299#M1071492</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once im connected to my RAVPN, I want to ensure traffic to a specific Public IP flows through my RAVPN tunnel at all times. Any advice?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shabeeb&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2020 17:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4110299#M1071492</guid>
      <dc:creator>shabeeb</dc:creator>
      <dc:date>2020-06-27T17:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC/FTD - RAVPN - Need to route specific IPs via RAVPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4110302#M1071493</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;How is your RAVPN configured?&lt;/P&gt;
&lt;P&gt;if you are using full tunnel then all ip addresses will be tunnelled back to the FTD. If using split tunnel, then you should include the public IP address in the tunnel to ensure it is tunnelled back.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the public IP address is actually hosted in the internet, then you will need a Nat rule from source outside to destination outside and Nat behind the outside interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2020 17:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4110302#M1071493</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-06-27T17:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC/FTD - RAVPN - Need to route specific IPs via RAVPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4110325#M1071496</link>
      <description>Hi Rob,&lt;BR /&gt;&lt;BR /&gt;Im using split tunneling &amp;amp; these IPs are part of the permitted ACL group.&lt;BR /&gt;&lt;BR /&gt;As you mentioned, these IPs are actually hosted on the internet. Let me do the NAT and check.&lt;BR /&gt;&lt;BR /&gt;TIA,&lt;BR /&gt;Shabeeb</description>
      <pubDate>Sat, 27 Jun 2020 19:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4110325#M1071496</guid>
      <dc:creator>shabeeb</dc:creator>
      <dc:date>2020-06-27T19:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC/FTD - RAVPN - Need to route specific IPs via RAVPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4110329#M1071498</link>
      <description>&lt;P&gt;Also, double check you’ve got a firewall rule permitting traffic to the internet&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2020 20:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4110329#M1071498</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-06-27T20:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC/FTD - RAVPN - Need to route specific IPs via RAVPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4112263#M1071633</link>
      <description>&lt;P&gt;Hi Rob,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately its not working. I can see the traffic is being routed via the firewall successfully, but the service is not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To give you a little insight into what im trying to achieve - (&lt;EM&gt;attached a small drawing of the main components being used, just something i did in paint&lt;/EM&gt;)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have Microsoft SFB Federation services enabled between sip.local.com &amp;amp; sip.remote.com&lt;/LI&gt;&lt;LI&gt;Everything (&lt;EM&gt;including IM, Calls, Content sharing&lt;/EM&gt;) works between My Local LAN &amp;amp; Remote Site&lt;/LI&gt;&lt;LI&gt;Everything (&lt;EM&gt;including IM, Calls, Content sharing&lt;/EM&gt;) works between external users &amp;amp; Remote Site (&lt;EM&gt;i.e. since the SFB services are published outside, anyone in the internet can login to SFB &amp;amp; work&lt;/EM&gt;)&lt;/LI&gt;&lt;LI&gt;Only IM works between My VPN Users &amp;amp; Remote Site&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Calls &amp;amp; Content sharing fails&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;U&gt;My observations&lt;/U&gt; -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remote site have enabled federation services to sip.local.com&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This URL is NATted to our Edge DMZ&lt;/LI&gt;&lt;LI&gt;This Edge DMZ then has all the relevant routes to my local network &amp;amp; my vpn network&lt;/LI&gt;&lt;LI&gt;Hence, as far as local SFB Edge is concerned, it has successful routes to both (&lt;EM&gt;local &amp;amp; vpn&lt;/EM&gt;) network&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I tried to telnet sip.remote.com on port 5061 - the response is as below&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;My Local LAN - it works fine&lt;/LI&gt;&lt;LI&gt;Open internet from home (&lt;EM&gt;without VPN&lt;/EM&gt;) - it works fine&lt;/LI&gt;&lt;LI&gt;VPN connected - it does not work&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So as far as Remote Site is concerned, they are receiving the traffic successfully&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;i.e. if it comes from my Local Subnet, everything works fine.&lt;/LI&gt;&lt;LI&gt;but if it comes from my VPN Subnet, the routing issues comes into play&lt;UL&gt;&lt;LI&gt;Im suspecting there is no reverse route from Remote Site to my VPN subnet&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Is my understanding correct???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shabeeb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 06:22:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4112263#M1071633</guid>
      <dc:creator>shabeeb</dc:creator>
      <dc:date>2020-07-02T06:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC/FTD - RAVPN - Need to route specific IPs via RAVPN</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4112269#M1071635</link>
      <description>Is the traffic towards the SIP service NATTED behind the outside interface of the FW?&lt;BR /&gt;If so, then the RAVPN networks should appear from the same source IP address. If traffic it is routed, then you would need to ensure that the other end has a route back. &lt;BR /&gt;&lt;BR /&gt;Run packet-tracer from the CLI and provide the output</description>
      <pubDate>Thu, 02 Jul 2020 06:33:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-ravpn-need-to-route-specific-ips-via-ravpn/m-p/4112269#M1071635</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-07-02T06:33:51Z</dc:date>
    </item>
  </channel>
</rss>

