<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inter-VLAN Routing configuration in Firepower in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262486#M1076855</link>
    <description>&lt;P&gt;I've demonstrated a lab for my issue. Please help to review my configuration.&lt;/P&gt;&lt;P&gt;All the Layer3 VLANs are on firepower and switch as L2 only access switch.&lt;/P&gt;&lt;P&gt;Thank you so much&lt;/P&gt;</description>
    <pubDate>Tue, 22 Dec 2020 16:51:46 GMT</pubDate>
    <dc:creator>SaintEvn</dc:creator>
    <dc:date>2020-12-22T16:51:46Z</dc:date>
    <item>
      <title>Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262330#M1076844</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I would like to configure inter-vlan routing in firepower(FMC) using VLAN sub interface.&lt;/P&gt;&lt;P&gt;I've created sub interfaces with separate VLAN ID on physical interface. And I've configure trunking port at the access switch side with appropriate gateway.&lt;/P&gt;&lt;P&gt;But the inter-vlan is still not working .&lt;/P&gt;&lt;P&gt;What do I need to do in Firepower (FMC) in order to work inter-vlan routing?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you so much all!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 11:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262330#M1076844</guid>
      <dc:creator>SaintEvn</dc:creator>
      <dc:date>2020-12-22T11:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262334#M1076845</link>
      <description>&lt;P&gt;FTD is a&amp;nbsp; more of zone-based firewall, and same-security-traffic&amp;nbsp; required to achieve intra and inter interface communication. ACP rule is required to make this work&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 11:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262334#M1076845</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-12-22T11:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262452#M1076848</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi,&lt;/P&gt;&lt;P&gt;I've also try with allow any Access Control Policy&amp;nbsp; but the inter-vlan is still not working .&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It was like I miss "ip routing" on core layer switch.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have 3 vlans (vlan 10, 11,12) and only vlan 10 is pintable form access switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also make sure " no ip routing" on access switch .But the inter-vlan on firepower still cannot work yet.&lt;/P&gt;&lt;P&gt;Do I need to miss out something in firepower ??&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 15:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262452#M1076848</guid>
      <dc:creator>SaintEvn</dc:creator>
      <dc:date>2020-12-22T15:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262461#M1076849</link>
      <description>&lt;P&gt;Can you post the switch config to look, how you configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is the VLAN Layer3&amp;nbsp; on Switch or FTD ? or both the places ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 15:55:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262461#M1076849</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-12-22T15:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262484#M1076854</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/916085"&gt;@SaintEvn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have NAT exemption rules setup, without them traffic could unintentially be natted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you ping the vlan10 ip address of the FTD from the access switch you would only expect to get a response from vlan10, you cannot be connected to one FTD interface (FTD vlan10) and ping through the FTD to the FTD's far interface (FTD vlan11), this would be denied - by design. You would need to ping through the FTD to a device connected to vlan11 (pc, printer etc). Obviously your ACP rules need to permit this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run packet-tracer from the CLI and provide the output for review.&lt;/P&gt;
&lt;P&gt;Provide a screenshot of your ACP for this traffic.&lt;/P&gt;
&lt;P&gt;Provide the output of "show nat detail"&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 16:45:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262484#M1076854</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-12-22T16:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262486#M1076855</link>
      <description>&lt;P&gt;I've demonstrated a lab for my issue. Please help to review my configuration.&lt;/P&gt;&lt;P&gt;All the Layer3 VLANs are on firepower and switch as L2 only access switch.&lt;/P&gt;&lt;P&gt;Thank you so much&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 16:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262486#M1076855</guid>
      <dc:creator>SaintEvn</dc:creator>
      <dc:date>2020-12-22T16:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262495#M1076856</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/916085"&gt;@SaintEvn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't have any interfaces configured in vlan11 or vlan12 on the switch, so I can only assume you are pinging vlan11 and vlan12 interfaces on the FTD from the switch itself which would be from vlan 10. Which as explained above will not work by design.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to connect some devices to the switch in vlan11 and vlan12 with a default gateway of the FTD and then ping "through" the FTD not "to" the FTD.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 17:01:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262495#M1076856</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-12-22T17:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262507#M1076857</link>
      <description>&lt;P&gt;Thank you for your suggestion but according to my understanding , I already have trunk port configured between switch and firepower. And I also configured allow any policy .So, it should be able to ping form vlan 10 to other vlan interfaces on FTD. That is what I usually configure in other firewalls and ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now, It is more like when we missed "ip routing" command on L3 switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 17:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262507#M1076857</guid>
      <dc:creator>SaintEvn</dc:creator>
      <dc:date>2020-12-22T17:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262510#M1076858</link>
      <description>&lt;P&gt;No that's incorrect. The FTD only responds to ICMP traffic sent to the interface that traffic comes in on (vlan10); you cannot send ICMP traffic through an interface to a far interface (vlan11 or vlan12), the same applied to ASA aswell. I stated test communication by pinging "through" the firewall not "to".&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 17:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262510#M1076858</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-12-22T17:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262530#M1076860</link>
      <description>&lt;P&gt;&lt;BR /&gt;I've assigned access port for VLAN 10, 11 and 12 .&lt;BR /&gt;Then I tried to ping from VLAN 10 client to VLAN 11 Client etc.&lt;BR /&gt;But still the same. Inter-vlan routing is not working.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 17:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262530#M1076860</guid>
      <dc:creator>SaintEvn</dc:creator>
      <dc:date>2020-12-22T17:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262551#M1076862</link>
      <description>&lt;P&gt;So you've connect a client device to each vlan 10, 11 and 12 with the default gateway for the client devices as the local FTD vlan interface?&lt;/P&gt;
&lt;P&gt;Can each client device ping their own local vlan interface IP address (default gateway)?&lt;/P&gt;
&lt;P&gt;Do you have nat configured? If yes, you might need a nat exemption rule.&lt;/P&gt;
&lt;P&gt;Run packet-tracer from the CLI of the FTD and provide the output for review.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 18:10:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262551#M1076862</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-12-22T18:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262603#M1076863</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes, each client device can ping their own default gateway. And there is no NAT on firepower.&lt;/P&gt;&lt;P&gt;I have captured some packet&lt;BR /&gt;- each VLAN client to each respective gateway and&lt;BR /&gt;-VLAN10 Client to other VLAN Client&lt;/P&gt;&lt;P&gt;I'm capturing from my lab so the capture files may be somehow difficult to view.&lt;BR /&gt;Very sorry for that and thank you so much for helping me&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 20:05:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262603#M1076863</guid>
      <dc:creator>SaintEvn</dc:creator>
      <dc:date>2020-12-22T20:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262616#M1076864</link>
      <description>&lt;P&gt;Are you logging traffic in ACP rules? if so check the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also run "system support firewall-engine-debug" command and filter on the source IP address of the computer you are running a ping from. Then run a ping, provide the output from that command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do the client devices you are running a ping to/from have a local firewall turned on that could block the ping response?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What was the output of packet-tracer?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 20:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262616#M1076864</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-12-22T20:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262983#M1076873</link>
      <description>&lt;P&gt;Thank you all for helping me to solve this issue . I reconfigure all sub-interface in firepower , create ACP Policy and try to ping from one vlan client to another vlan client&amp;nbsp; and it's working !&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 14:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4262983#M1076873</guid>
      <dc:creator>SaintEvn</dc:creator>
      <dc:date>2020-12-23T14:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4314334#M1079642</link>
      <description>&lt;P&gt;hello i have same problem ACP is correct i allow everything but host can not ping. all network can connect to FMC, and ping default gateway. What was the problem?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 09:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4314334#M1079642</guid>
      <dc:creator>shotalezhava</dc:creator>
      <dc:date>2021-03-26T09:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4319660#M1079896</link>
      <description>&lt;P&gt;I am configuring on FMC 6.7 to FDM 1120 in routed mode with 4 inside interfaces and a single outside interface--have the same problem. I allow inside to inside traffic but cannot pass traffic between inside interfaces.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-04-06 212402.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108268iD7854A0EA59E6405/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-04-06 212402.png" alt="Screenshot 2021-04-06 212402.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-04-06 212723.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108269i15322F314A672AA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-04-06 212723.png" alt="Screenshot 2021-04-06 212723.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 01:29:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4319660#M1079896</guid>
      <dc:creator>rgrashorn</dc:creator>
      <dc:date>2021-04-07T01:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4319769#M1079904</link>
      <description>&lt;P&gt;If pc can ping default gateway turn off windows firewall and allow ping on windowa&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 07:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4319769#M1079904</guid>
      <dc:creator>shotalezhava</dc:creator>
      <dc:date>2021-04-07T07:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Inter-VLAN Routing configuration in Firepower</title>
      <link>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4926909#M1104440</link>
      <description>&lt;P&gt;Can you post, I want to run the same thing for my home network to reduce the equipment I need to get to my server.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 02:37:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inter-vlan-routing-configuration-in-firepower/m-p/4926909#M1104440</guid>
      <dc:creator>bonojeta</dc:creator>
      <dc:date>2023-09-21T02:37:49Z</dc:date>
    </item>
  </channel>
</rss>

