<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot VPN through a Cisco Firepower 1010 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-vpn-through-a-cisco-firepower-1010/m-p/4413170#M1081291</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a 1010 Firepower on the edge with 2 S2S VPN connections established on it.&lt;/P&gt;&lt;P&gt;Now when I try to connect from a client inside of the 1010 to a VPN Gateway on the internet, it is not going through, any hints on where to troubleshoot? as these devices are limited in that&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 16:01:06 GMT</pubDate>
    <dc:creator>MSakr</dc:creator>
    <dc:date>2021-06-04T16:01:06Z</dc:date>
    <item>
      <title>Cannot VPN through a Cisco Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/cannot-vpn-through-a-cisco-firepower-1010/m-p/4413170#M1081291</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a 1010 Firepower on the edge with 2 S2S VPN connections established on it.&lt;/P&gt;&lt;P&gt;Now when I try to connect from a client inside of the 1010 to a VPN Gateway on the internet, it is not going through, any hints on where to troubleshoot? as these devices are limited in that&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 16:01:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-vpn-through-a-cisco-firepower-1010/m-p/4413170#M1081291</guid>
      <dc:creator>MSakr</dc:creator>
      <dc:date>2021-06-04T16:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot VPN through a Cisco Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/cannot-vpn-through-a-cisco-firepower-1010/m-p/4413254#M1081298</link>
      <description>&lt;P&gt;I've seen this at time when the internal system needed to use IPsec and the udp/500 ports were already in use by the firewall interface that terminates the other IPsec tunnels. One solution is to use a static NAT for that client so that it has it's own public IP. Another is to see if it can negotiate with the distant end using udp/4500 (NAT-Traversal).&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 18:41:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-vpn-through-a-cisco-firepower-1010/m-p/4413254#M1081298</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-04T18:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot VPN through a Cisco Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/cannot-vpn-through-a-cisco-firepower-1010/m-p/4413621#M1081320</link>
      <description>&lt;P&gt;Hi Marvin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what I thought initially that the same port might be used.&lt;/P&gt;&lt;P&gt;I was thinking to assign another public IP for the S2S tunnels or another IP for the public interface , whichever might be feasible on 1010 or easier.. your thoughts if it is possible? as I cannot change the peer VPN GW,&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 12:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-vpn-through-a-cisco-firepower-1010/m-p/4413621#M1081320</guid>
      <dc:creator>MSakr</dc:creator>
      <dc:date>2021-06-06T12:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot VPN through a Cisco Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/cannot-vpn-through-a-cisco-firepower-1010/m-p/4413663#M1081328</link>
      <description>&lt;P&gt;Site to site tunnels terminating on the FTD device must use the interface address.&lt;/P&gt;
&lt;P&gt;You can verify the active ones are using the port connection with "show conn | i 500".&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 14:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-vpn-through-a-cisco-firepower-1010/m-p/4413663#M1081328</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-06T14:57:25Z</dc:date>
    </item>
  </channel>
</rss>

