<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Based Routing on FTD (route-map) managed by FDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4391525#M1080234</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Flex config object doesn't give possibility to use route-map command it says&amp;nbsp;&lt;/P&gt;&lt;P&gt;Blacklisted cli error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any other way to resolve this with&amp;nbsp;&lt;SPAN&gt;FTD 6.6.1&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Apr 2021 13:27:08 GMT</pubDate>
    <dc:creator>milanjovanovic82</dc:creator>
    <dc:date>2021-04-22T13:27:08Z</dc:date>
    <item>
      <title>Policy Based Routing on FTD (route-map) managed by FDM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4187873#M1076063</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;on an FPR-1010 device (Version FTD 6.6.1), managed by FDM I want to do a simple static load distribution by using policy based routing.&lt;/P&gt;&lt;P&gt;On CISCO ASA it is easy like this example:&lt;/P&gt;&lt;PRE&gt;interface Vlan1
 nameif inside
 policy-route route-map ROUTEMAP-INET2-OUT

object-group service g-TCP-PORTS-INET2 tcp
 port-object eq www
 port-object eq https

access-list ROUTEMAP-ACL-INET2-OUT extended permit tcp any any object-group g-TCP-PORTS-DSL
access-list ROUTEMAP-ACL-INET2-OUT extended permit &amp;lt;WHATEVER-YOU-WANT-TO-SEND-VIA-INET2&amp;gt;

route-map ROUTEMAP-INET2-OUT permit 10
 match ip address ROUTEMAP-ACL-INET2-OUT
 set ip next-hop &amp;lt;IP-ADDRESS-OF-INET2-GATEWAY&amp;gt;&lt;/PRE&gt;&lt;P&gt;Implementing this on a FPR-1010 I have to use Smart CLI as explained in&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd-fdm-route-maps.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd-fdm-route-maps.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But I'm unable to configure next-hop (last line of code above)! As I saw the manual is only related to BGP Routing.&lt;/P&gt;&lt;P&gt;Any ideas to implement it without an FMC appliance?&lt;/P&gt;&lt;P&gt;Thanks for all input.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 08:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4187873#M1076063</guid>
      <dc:creator>INFOTECH.jw</dc:creator>
      <dc:date>2020-11-24T08:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing on FTD (route-map) managed by FDM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4187939#M1076064</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I don't think you have other options. Either FMC GUI or FlexConfig.&lt;BR /&gt;&lt;BR /&gt;*** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Nov 2020 09:32:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4187939#M1076064</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-11-24T09:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing on FTD (route-map) managed by FDM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4391525#M1080234</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Flex config object doesn't give possibility to use route-map command it says&amp;nbsp;&lt;/P&gt;&lt;P&gt;Blacklisted cli error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any other way to resolve this with&amp;nbsp;&lt;SPAN&gt;FTD 6.6.1&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 13:27:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4391525#M1080234</guid>
      <dc:creator>milanjovanovic82</dc:creator>
      <dc:date>2021-04-22T13:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing on FTD (route-map) managed by FDM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4427232#M1081956</link>
      <description>&lt;P&gt;how did you solve the problem?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 12:54:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4427232#M1081956</guid>
      <dc:creator>AlexeyFokanov31798</dc:creator>
      <dc:date>2021-07-02T12:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing on FTD (route-map) managed by FDM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4479568#M1084194</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;"set ip next-hop" can be configured by using Smart CLI as the screenshot below.&lt;/PRE&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="next-hop.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/133202i0B2AFA01B74E0064/image-size/large?v=v2&amp;amp;px=999" role="button" title="next-hop.jpg" alt="next-hop.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I found that anything you can do in FMC, actually you can do it in FDM as well. FDM doesn't provide a GUI for all configurations, but basically you can do it by using "API Explorer".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, FDM doens't provide a way defining "set interface" command in route-map object, but you can do it by editing "route-map" object with the following code from "API Explorer". How do you know "id", "type", "version" and "name" of a interface? check &lt;STRONG&gt;Interface&amp;nbsp;&lt;/STRONG&gt;object from "API Explorer" you will get the answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"version"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"dqxzjs2lg2tlc"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"name"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"routemap01"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"description"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;null&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"entries"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;[&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"sequence"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"action"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"PERMIT"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"interfaces"&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;[&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;{&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"id":&amp;nbsp;"8d6c41df-3e5f-465b-8e5a-d336b282f93f",&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"type":&amp;nbsp;"physicalinterface",&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"version":&amp;nbsp;"mz2ho36wazdnw",&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"name":&amp;nbsp;"outside"&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;],&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 04 Oct 2021 17:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4479568#M1084194</guid>
      <dc:creator>sparkf1</dc:creator>
      <dc:date>2021-10-04T17:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing on FTD (route-map) managed by FDM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4479579#M1084195</link>
      <description>&lt;P&gt;You can define route-map with "API Explorer" from FDM.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 17:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4479579#M1084195</guid>
      <dc:creator>sparkf1</dc:creator>
      <dc:date>2021-10-04T17:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing on FTD (route-map) managed by FDM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4683792#M1093263</link>
      <description>&lt;P&gt;How do we attach this route-map to an interface?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 17:43:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4683792#M1093263</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2022-09-08T17:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing on FTD (route-map) managed by FDM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4683977#M1093271</link>
      <description>&lt;P&gt;I believe it is only possible via FlexConfig using the command&lt;/P&gt;
&lt;PRE&gt;policy-route route-map YOUR-ROUTEMAP-NAME&lt;/PRE&gt;
&lt;P&gt;BR&lt;BR /&gt;Rick&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 06:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4683977#M1093271</guid>
      <dc:creator>rschlayer</dc:creator>
      <dc:date>2022-09-09T06:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing on FTD (route-map) managed by FDM</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4684278#M1093275</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;To attach it to inside interface, i think it will be-&lt;/P&gt;
&lt;P&gt;interface Ethxx&lt;/P&gt;
&lt;PRE&gt;policy-route route-map YOUR-ROUTEMAP-NAME&lt;/PRE&gt;
&lt;P&gt;But I am afraid to test it in a live environment &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 14:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-on-ftd-route-map-managed-by-fdm/m-p/4684278#M1093275</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2022-09-09T14:50:39Z</dc:date>
    </item>
  </channel>
</rss>

