<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD 1010 cant ping between ports in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155287#M1074091</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1089849"&gt;@S3C&lt;/a&gt; Glad to hear it is working.&lt;/P&gt;
&lt;P&gt;However that sounds like the ADDC server is using the switch as it's default gateway, correct? If so that's less than ideal, as you have 2 gateways on the same network (192.168.10.1 and 192.168.10.10), you should set the default gateway of all host servers to be the FTD, in the correct VLAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An IP address and gateway on the switch would only be used for management.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Sep 2020 13:36:26 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2020-09-22T13:36:26Z</dc:date>
    <item>
      <title>FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155079#M1074066</link>
      <description>&lt;P&gt;So this is a LAN setup &amp;amp; using GUI but can also use cli if needed.&lt;/P&gt;&lt;P&gt;Ive been troubleshooting this for a few days and I think FTD is blocking the access between the port 3 and port 1.&lt;/P&gt;&lt;P&gt;Here´s the setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Host - 192.168.3.5/24&lt;/P&gt;&lt;P&gt;FTD Port 3 - routed status - 192.168.3.1/24&lt;/P&gt;&lt;P&gt;FTD Port 1 - sub-int1.10, vlan10 - 192.168.10.1/24&lt;/P&gt;&lt;P&gt;SW Port 10 - sub-int1.10, vlan10 - 192.168.10.10/24 (trunk)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Host -&amp;gt; Port 3 (FTD) -&amp;gt; Port 1 (FTD) -&amp;gt; Port 10 (SW)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Host CANT ping port 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;But....&lt;/P&gt;&lt;P&gt;FTD can ping Host&lt;/P&gt;&lt;P&gt;Host can ping FTD&lt;/P&gt;&lt;P&gt;FTD can ping SW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have setuped ACL rule to allow any any any any, also a static route for traffic through sub-int1.10 &amp;amp; port 3 but still doesnt work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help me in what I have done wrong or missed? Also, let me know if need to add more info&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot, much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 07:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155079#M1074066</guid>
      <dc:creator>S3C</dc:creator>
      <dc:date>2020-09-22T07:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155088#M1074067</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1089849"&gt;@S3C&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can only ping an FTD's interface that traffic comes in on (Port 3), you cannot send ICMP traffic through an interface to a far interface, this is denied by design and you cannot change it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your ACL you've setup applies to traffic "through" the FTD, not "to" the FTD - it would not work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 07:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155088#M1074067</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-22T07:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155094#M1074069</link>
      <description>&lt;P&gt;Hi Rob!&lt;/P&gt;&lt;P&gt;Thanks for answering.&lt;/P&gt;&lt;P&gt;I wrote wrong above but updated now.&lt;/P&gt;&lt;P&gt;Let me show you the end goal here as to why Im asking how to do this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Host -&amp;gt; Port 3 (FTD) -&amp;gt; Port 1 (FTD, with sub-ints) -&amp;gt; Port 10 (SW, with VLANs) -&amp;gt; Port 1 (SW, with VLANs) -&amp;gt; Port 1 (SRV, with VMs)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Host - 192.168.3.5/24&lt;/P&gt;&lt;P&gt;FTD Port 3 - routed status - 192.168.3.1/24&lt;/P&gt;&lt;P&gt;FTD Port 1 - sub-int1.10, vlan10 - 192.168.10.1/24&lt;/P&gt;&lt;P&gt;SW Port 10 - sub-int1.10, vlan10 - 192.168.10.10/24 (trunk)&lt;/P&gt;&lt;P&gt;SW Port 1 -&amp;nbsp;sub-int1.10, vlan10 (trunk)&lt;/P&gt;&lt;P&gt;SRV Port 1 - 7 VMs where 1 is tagged vlan10 and is a ADDC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bear in mind the VSRV has 7 machines which each one got their own vlan on SW &amp;amp; Sub-int on FTD.&lt;/P&gt;&lt;P&gt;Ping from FTD to VSRV &amp;amp; vice versa is OK, all is working as planned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As my end goal here, is that the host would be able to join the domain &amp;amp; then at END in a few months be able to RDP to all other VMs (though at this time I just want to get it to be joined to the domain).&lt;/P&gt;&lt;P&gt;But I CANT ping port 1 vlan10 where ADDC is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached a diagram too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 07:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155094#M1074069</guid>
      <dc:creator>S3C</dc:creator>
      <dc:date>2020-09-22T07:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155097#M1074070</link>
      <description>&lt;P&gt;Ok, so you aren't ping the FTD's far interfaces, rather you are pinging through the FTD to the switches SVI and not receiving a response?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You already have a permit ip any any rule, please provide a screenshot, just for confirmation.&lt;/P&gt;
&lt;P&gt;Check you aren't unintentially natting on the FTD, provide the output of "show nat detail" for review if you wish.&lt;/P&gt;
&lt;P&gt;Can the FTD ping the VSRV ip addresses?&lt;/P&gt;
&lt;P&gt;Check routing on the switch and FTD, provide the routing table from both if you wish confirmation.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 07:53:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155097#M1074070</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-22T07:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155102#M1074071</link>
      <description>&lt;P&gt;Nope, correct. Just trying to ping the Sub-ints/SVI from host.&amp;nbsp;As ping to SVIs from FTD is OK.&lt;/P&gt;&lt;P&gt;Host trying to ping sub-ints IP which is 192.168.10.1, but getting timeout.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS of ACL is attached.&lt;/P&gt;&lt;P&gt;No NAT rule as nothing will have internet access nor access website. everything will be LAN.&lt;/P&gt;&lt;P&gt;Correct, FTD can ping everything. Host is the only one who cant ping Sub-ints/SVI but it can ping FTD.&lt;/P&gt;&lt;P&gt;Routing on FTD attached (GW is host network) + no routing on SW as the 2 ints used are Trunk and apart of same VLANs.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;How should the routing be? (not used to this new GUI routing setup)&lt;/P&gt;&lt;P&gt;Interface: (sub-int or host)?&lt;/P&gt;&lt;P&gt;Networks: (hosts or the sub-ints)?&lt;/P&gt;&lt;P&gt;GW: host, ftd or sub-ints)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Rob!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 08:54:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155102#M1074071</guid>
      <dc:creator>S3C</dc:creator>
      <dc:date>2020-09-22T08:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155140#M1074075</link>
      <description>&lt;P&gt;Still un-clear, just provide "show run" from both the FTD and switch it will make things easier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is you intention to route all inter-vlan traffic through the FTD? If so the switch does not need IP addresses per VLAN, only 1 for management. The virtual servers would use the FTD as the default gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the IP address of the Virtual Server (ADDC) and can it ping the switch?&lt;/P&gt;
&lt;P&gt;What is the default gateway of the ADDC, 192.168.10.10 (switch) or 192.168.10.1 (FTD)? Regardless if it's in the same VLAN it should be able to ping 192.168.10.1&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 09:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155140#M1074075</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-22T09:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155157#M1074077</link>
      <description>&lt;P&gt;Correct, all access, traffic routes, denies from users, hosts etc is going through FTD.&lt;/P&gt;&lt;P&gt;Logical plan is that ALL traffic is going to go through FTD, both ways through 1 interface.&lt;/P&gt;&lt;P&gt;So if a VSRV VM wants to talk to another VSRV then it has to go through the FTD first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I then dont need trunk ports with the different vlans?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Virtual Server (ADDC) is only tagged with VLAN10, no IP. Yep and it can also ping the FW (vice versa)&lt;/P&gt;&lt;P&gt;Default GW of ADDC havent set as only tagged it with VLAN10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is totally fine, FTD to VSRV (ADDC) is OK (pingable).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is at FTD. Host cant ping the VLAN10 (ADDC) (192.168.10.1).&lt;/P&gt;&lt;P&gt;Host port 3&lt;/P&gt;&lt;P&gt;Vlan10 port 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Host GW: 192.168.3.1 (set on port 3 on FTD)&lt;/P&gt;&lt;P&gt;Host IP: 192.168.3.5 (set on host machine)&lt;/P&gt;&lt;P&gt;Vlan10: 192.168.10.1 (set on sub-int)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As if FTD is blocking traffic from port 3 to port 1 even though rules are set for allow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Less un-clear now? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ill update with config from both SW &amp;amp; FTD if still needed in about 1h.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks Rob,&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 09:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155157#M1074077</guid>
      <dc:creator>S3C</dc:creator>
      <dc:date>2020-09-22T09:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155160#M1074078</link>
      <description>&lt;P&gt;"The issue is at FTD. Host cant ping the VLAN10 (ADDC) (192.168.10.1)." &amp;lt;&amp;lt;&amp;lt; is this IP address a typo? 192.168.10.1 is the FTD's interface IP address, which as explained in the first respond will never respond to a ping from "Host".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it is a typo and you are indeed pinging through the FTD to the ADDC on whatever IP address is configured can you run packet-tracer from the CLI and provide the full output.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 09:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155160#M1074078</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-22T09:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155193#M1074082</link>
      <description>&lt;P&gt;Ah yes. its a typo. Meant to be 192.168.10.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ADDC/SRV can ping 192.168.10.1 &amp;amp; 10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be more clear:&lt;/P&gt;&lt;P&gt;192.168.10.10 = VLAN10 on SW&lt;/P&gt;&lt;P&gt;192.168.10.1 = sub-int on FTD with tag vlan10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correct, I want to ping through the FTD to ADDC but it stops at the FTD as cant ping 192.168.10.10. (been trying with .1 as well just because its a sub-int and thought it would respons to ping as when pinging from SW it responds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will provide the full output in a sec.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 11:07:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155193#M1074082</guid>
      <dc:creator>S3C</dc:creator>
      <dc:date>2020-09-22T11:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155200#M1074083</link>
      <description>&lt;P&gt;Ok, so does the switch have a default route/gateway?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 11:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155200#M1074083</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-22T11:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155210#M1074084</link>
      <description>&lt;P&gt;Nope, set default gw on the VLANs towards the sub-ints on the FTD?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No router in network and 7 sub-ints going through the trunk to FTD, so I cant set 1 of them as a default GW as all 7 will be used. Also all traffic is tagged except the host.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Working on the output &amp;amp; conf btw, havent forgot.&lt;/P&gt;&lt;P&gt;Tracert times out on the first jump which I think that FTD is blocking as it would otherwise show 192.168.10.1 as next hop if it would the host through right?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:11:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155210#M1074084</guid>
      <dc:creator>S3C</dc:creator>
      <dc:date>2020-09-22T12:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155239#M1074085</link>
      <description>&lt;P&gt;Actually the default gateway would only be required if you wanted to communicate with the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the default gateway of the ADDC server the FTD (192.168.10.1)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was referring to packet-tracer not tracert, provide that and the configs and we should have a clearer picture.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:35:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155239#M1074085</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-22T12:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155283#M1074090</link>
      <description>&lt;P&gt;Hi Rob!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setting default GW on the VLAN solved the problem. I can now ping ADDC from host &amp;amp; domain join.&lt;/P&gt;&lt;P&gt;Thanks a lot for the support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much appreciated&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 13:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155283#M1074090</guid>
      <dc:creator>S3C</dc:creator>
      <dc:date>2020-09-22T13:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 cant ping between ports</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155287#M1074091</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1089849"&gt;@S3C&lt;/a&gt; Glad to hear it is working.&lt;/P&gt;
&lt;P&gt;However that sounds like the ADDC server is using the switch as it's default gateway, correct? If so that's less than ideal, as you have 2 gateways on the same network (192.168.10.1 and 192.168.10.10), you should set the default gateway of all host servers to be the FTD, in the correct VLAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An IP address and gateway on the switch would only be used for management.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 13:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-cant-ping-between-ports/m-p/4155287#M1074091</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-22T13:36:26Z</dc:date>
    </item>
  </channel>
</rss>

