<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Flexconfig not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4389145#M1080109</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i got the solution.&lt;/P&gt;&lt;P&gt;anyway the default route to ISP1 will take all routes from routing table. so below configuration is planned and working now.&lt;/P&gt;&lt;P&gt;create extended ACL for specific subnet 10.10.10.0/24 which you want to redirect into ISP2 (standard ACL not support for Flex config suggested from Cisco TAC)&lt;/P&gt;&lt;P&gt;create route-map and add the extended ACL also specify the next-hop 123.123.123.123 as Firewall ISP2 gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create flexconfig&lt;/P&gt;&lt;P&gt;interface Port-channel10&lt;BR /&gt;policy-route route-map&amp;nbsp;&lt;STRONG&gt;insert route-map object&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then deploy the flex config.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Apr 2021 05:13:51 GMT</pubDate>
    <dc:creator>Vishnu_RR</dc:creator>
    <dc:date>2021-04-19T05:13:51Z</dc:date>
    <item>
      <title>Flexconfig not working</title>
      <link>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388336#M1080074</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we have ISP1 and ISP2. There is metric 1 for ISP1 and metric 2 for ISP2. both ISP are in separate zone. when i create flexconfig for specific souce with ISP2 which is not working and still hitting ISP1 only.\&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have configured below flexconfig.&lt;/P&gt;&lt;P&gt;1. standard access-list = 10.10.10.0/24&lt;/P&gt;&lt;P&gt;2. route-map&lt;/P&gt;&lt;P&gt;3. flexconfig&lt;/P&gt;&lt;P&gt;route-map $Route-Map permit 10&lt;/P&gt;&lt;P&gt;set ip next-hop $ISP2_GW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Port-channel2&lt;BR /&gt;policy-route route-map $Route-Map&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do i need to do any more changes&lt;/P&gt;&lt;P&gt;When i do the packet-tracer shows 10.10.10.0/24 is hitting ISP1 only.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 12:14:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388336#M1080074</guid>
      <dc:creator>Vishnu_RR</dc:creator>
      <dc:date>2021-04-16T12:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: Flexconfig not working</title>
      <link>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388375#M1080075</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1129046"&gt;@Vishnu_RR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you using FMC or FDM to configure this? Which version?&lt;/P&gt;
&lt;P&gt;Can you provide the configuration output (screenshot and running config).&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 13:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388375#M1080075</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-04-16T13:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Flexconfig not working</title>
      <link>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388379#M1080076</link>
      <description>&lt;P&gt;Hi thanks for your response.&lt;/P&gt;&lt;P&gt;FMC and FTD version is 6.6.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we configured below objects&lt;BR /&gt;standard ACL = 10.10.10./24&lt;BR /&gt;Route-map = sequence number 10 and standard ACL called here and next-hop 123.123.123.123(ISP2 Gateway) is specified.&lt;BR /&gt;flex-object = ISP2GW - 123.123.123.123&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Flexconfig configuration&lt;BR /&gt;route-map $route-map-name permit 10&lt;BR /&gt;set ip next-hop $ISP2GW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Port-channel10&lt;BR /&gt;policy-route route-map $route-map-name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i did the packet-tracer for souce 10.10.10.10 and destination 8.8.8.8 is showing ISP1 is the next-hop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 13:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388379#M1080076</guid>
      <dc:creator>Vishnu_RR</dc:creator>
      <dc:date>2021-04-16T13:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Flexconfig not working</title>
      <link>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388393#M1080077</link>
      <description>&lt;P&gt;Please provide the output of:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show run int Po10&lt;BR /&gt;show run route-map&lt;BR /&gt;show run access-list&lt;BR /&gt;show policy-route&lt;/P&gt;
&lt;P&gt;show route&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Po10 is the inside interface right?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 13:39:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388393#M1080077</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-04-16T13:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: Flexconfig not working</title>
      <link>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388422#M1080078</link>
      <description>Yes Po10 is the inside interface&lt;BR /&gt;</description>
      <pubDate>Fri, 16 Apr 2021 14:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4388422#M1080078</guid>
      <dc:creator>Vishnu_RR</dc:creator>
      <dc:date>2021-04-16T14:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: Flexconfig not working</title>
      <link>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4389145#M1080109</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i got the solution.&lt;/P&gt;&lt;P&gt;anyway the default route to ISP1 will take all routes from routing table. so below configuration is planned and working now.&lt;/P&gt;&lt;P&gt;create extended ACL for specific subnet 10.10.10.0/24 which you want to redirect into ISP2 (standard ACL not support for Flex config suggested from Cisco TAC)&lt;/P&gt;&lt;P&gt;create route-map and add the extended ACL also specify the next-hop 123.123.123.123 as Firewall ISP2 gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create flexconfig&lt;/P&gt;&lt;P&gt;interface Port-channel10&lt;BR /&gt;policy-route route-map&amp;nbsp;&lt;STRONG&gt;insert route-map object&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then deploy the flex config.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 05:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flexconfig-not-working/m-p/4389145#M1080109</guid>
      <dc:creator>Vishnu_RR</dc:creator>
      <dc:date>2021-04-19T05:13:51Z</dc:date>
    </item>
  </channel>
</rss>

