<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower 4110 intra-interface traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4470617#M1083858</link>
    <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;I have a scenario, where I have to manage the east-west traffic and I have only one inside interface for LAN. So is this possible the traffic enters and exits the same interface in FTD? if yes, then how can I achieve this.&lt;/P&gt;&lt;P&gt;thanks.....&lt;/P&gt;</description>
    <pubDate>Tue, 21 Sep 2021 11:12:24 GMT</pubDate>
    <dc:creator>usman.works1985</dc:creator>
    <dc:date>2021-09-21T11:12:24Z</dc:date>
    <item>
      <title>Firepower 4110 intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4470617#M1083858</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;I have a scenario, where I have to manage the east-west traffic and I have only one inside interface for LAN. So is this possible the traffic enters and exits the same interface in FTD? if yes, then how can I achieve this.&lt;/P&gt;&lt;P&gt;thanks.....&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 11:12:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4470617#M1083858</guid>
      <dc:creator>usman.works1985</dc:creator>
      <dc:date>2021-09-21T11:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 4110 intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4470691#M1083860</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;This is doable in FTD. By default intra-interface traffic is allowed by&lt;BR /&gt;default. Just make sure to avoid ICMP redirects which can bypass FTD. I&lt;BR /&gt;suggest creating two sub-interfaces on the same physical interface to&lt;BR /&gt;ensure that traffic enters and exits FTD.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Sep 2021 12:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4470691#M1083860</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-09-21T12:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 4110 intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4471379#M1083902</link>
      <description>&lt;P&gt;Hi Mohommed,&lt;/P&gt;&lt;P&gt;Thanks for your response. In my scenario the Firewall is not the Gateway, but still it is passing all the traffic... In that case I cannot have two or multiple sub-interfaces instead one physical interface... would it still be applicable?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 14:40:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4471379#M1083902</guid>
      <dc:creator>usman.works1985</dc:creator>
      <dc:date>2021-09-22T14:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 4110 intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4471488#M1083904</link>
      <description>&lt;P&gt;If it isn't the gateway and only has a single interface how is it passing all the traffic?&lt;/P&gt;
&lt;P&gt;If it is set as the routing next hop by the gateway it can work. Traffic can go in and come out of the same interface (physical and logical). Of course you will need policies set to inspect, log etc.&lt;/P&gt;
&lt;P&gt;It's a bit of an odd configuration that way and normally we would recommend separate interfaces for various reasons.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 16:26:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4471488#M1083904</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-09-22T16:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 4110 intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4471540#M1083907</link>
      <description>&lt;P&gt;Hi Marvin,&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to answer your question my FTD is connected with ACI fabric and the FABRIC is acting as a gateway for all the services... also the the fabric will redirect the traffic toward FTD with the help of PBR and FTD will inspect and send the back from the same interface...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 17:20:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-4110-intra-interface-traffic/m-p/4471540#M1083907</guid>
      <dc:creator>usman.works1985</dc:creator>
      <dc:date>2021-09-22T17:20:04Z</dc:date>
    </item>
  </channel>
</rss>

