<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Any Connect VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/any-connect-vpn/m-p/4161192#M1074398</link>
    <description>&lt;P&gt;Hi Tech guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in my Internet edge deployment, My FTD (21110) is behind the ASR1000 Router(Internet Gateway). I want to allow&amp;nbsp; any connect vpn clients to establish vpn connection to&amp;nbsp; FTD&amp;nbsp; via NAT Configured on ASR1000. From the Firewall perspective, Is there any Special configuration on firepower&amp;nbsp; e.g related to NAT/PAT to access the Local LAN subnets from Internet?&amp;nbsp; Any connection VPN configurations will be done FTD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 04 Oct 2020 08:02:55 GMT</pubDate>
    <dc:creator>Learnercisco</dc:creator>
    <dc:date>2020-10-04T08:02:55Z</dc:date>
    <item>
      <title>Any Connect VPN</title>
      <link>https://community.cisco.com/t5/network-security/any-connect-vpn/m-p/4161192#M1074398</link>
      <description>&lt;P&gt;Hi Tech guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in my Internet edge deployment, My FTD (21110) is behind the ASR1000 Router(Internet Gateway). I want to allow&amp;nbsp; any connect vpn clients to establish vpn connection to&amp;nbsp; FTD&amp;nbsp; via NAT Configured on ASR1000. From the Firewall perspective, Is there any Special configuration on firepower&amp;nbsp; e.g related to NAT/PAT to access the Local LAN subnets from Internet?&amp;nbsp; Any connection VPN configurations will be done FTD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Oct 2020 08:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/any-connect-vpn/m-p/4161192#M1074398</guid>
      <dc:creator>Learnercisco</dc:creator>
      <dc:date>2020-10-04T08:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Any Connect VPN</title>
      <link>https://community.cisco.com/t5/network-security/any-connect-vpn/m-p/4161193#M1074399</link>
      <description>&lt;P&gt;Steps :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. You need NAT on ASR 1000 Public to PrivateIP ( allocated on FTD)&lt;/P&gt;
&lt;P&gt;2. follow below guide to RAVPN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/212424-anyconnect-remote-access-vpn-configurati.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/212424-anyconnect-remote-access-vpn-configurati.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. You need to have ACP/ ACL should be in place what resouce required access for the VPN subnet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope make sense ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Oct 2020 08:06:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/any-connect-vpn/m-p/4161193#M1074399</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-10-04T08:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Any Connect VPN</title>
      <link>https://community.cisco.com/t5/network-security/any-connect-vpn/m-p/4161198#M1074400</link>
      <description>&lt;P&gt;thanks balaje for your reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1.&lt;STRONG&gt; You need NAT on ASR 1000 Public to PrivateIP ( allocated on FTD)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;The NAT ACL on ASR1K will include the FTD Outside IP address which makes sense.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2. follow below guide to RAVPN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have FMC ,The concept will be the same.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. &lt;STRONG&gt;You need to have ACP/ ACL should be in place what resouce required access for the VPN subnet.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Yes Correct. Access to Service VLAN in DMZ.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SSL Certificate&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we can generate Self signed certificated and map this certificate to our domain (e.g vpn.cisco.com) on the FTD, as its shown in the guide.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Oct 2020 08:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/any-connect-vpn/m-p/4161198#M1074400</guid>
      <dc:creator>Learnercisco</dc:creator>
      <dc:date>2020-10-04T08:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Any Connect VPN</title>
      <link>https://community.cisco.com/t5/network-security/any-connect-vpn/m-p/4161233#M1074409</link>
      <description>&lt;P&gt;&lt;STRONG&gt;SSL Certificate&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;we can generate Self signed certificated and map this certificate to our domain (e.g vpn.cisco.com) on the FTD, as its shown in the guide.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;BB - if this is external i would advise CA authority to sign. ( like Godaddy or DigiCert)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Oct 2020 12:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/any-connect-vpn/m-p/4161233#M1074409</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-10-04T12:40:08Z</dc:date>
    </item>
  </channel>
</rss>

