<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 1010 Unable to Connect to LAN Devices in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504481#M1085179</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1277341"&gt;@mlandavazo&lt;/a&gt; I'm not sure what your intention is by using the diagnostic interface? The Diagnostic interface only allows management traffic, and does not allow through traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connect to a data interface, assign an IP address and ensure this is a member of the "inside_zone" zone, write your NAT and ACP rules referring to the "inside_zone".&lt;/P&gt;</description>
    <pubDate>Wed, 17 Nov 2021 21:24:40 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2021-11-17T21:24:40Z</dc:date>
    <item>
      <title>Firepower 1010 Unable to Connect to LAN Devices</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504469#M1085175</link>
      <description>&lt;P&gt;I've got a Firepower 1010 set up (FTD via FDM) as a remote VPN device and I am unable to see devices on the LAN when I connect to the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The device is connected to the LAN via the Management interface, where it is automatically assigned an IP address on the LAN by the management network. What do I need to do to see my LAN devices while connected to VPN&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 20:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504469#M1085175</guid>
      <dc:creator>mlandavazo</dc:creator>
      <dc:date>2021-11-17T20:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 Unable to Connect to LAN Devices</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504471#M1085176</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1277341"&gt;@mlandavazo&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;You need to configure an Access Control rule from source "outside" to destination "inside" permitting traffic, you don't have that currently.&lt;/P&gt;
&lt;P&gt;You also need a NAT exemption rule between the inside network and the outside (RAVPN) network that does not translate the traffic. &lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 20:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504471#M1085176</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-11-17T20:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 Unable to Connect to LAN Devices</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504473#M1085177</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Thank you, I had an Access Control rule like that in place but was still not able to connect, so NAT is most likely the issue. Is the attached rule what I should implement?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 21:08:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504473#M1085177</guid>
      <dc:creator>mlandavazo</dc:creator>
      <dc:date>2021-11-17T21:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 Unable to Connect to LAN Devices</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504474#M1085178</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;I found some info on NAT Exempt rules and made the attached changes.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 21:14:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504474#M1085178</guid>
      <dc:creator>mlandavazo</dc:creator>
      <dc:date>2021-11-17T21:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 Unable to Connect to LAN Devices</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504481#M1085179</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1277341"&gt;@mlandavazo&lt;/a&gt; I'm not sure what your intention is by using the diagnostic interface? The Diagnostic interface only allows management traffic, and does not allow through traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connect to a data interface, assign an IP address and ensure this is a member of the "inside_zone" zone, write your NAT and ACP rules referring to the "inside_zone".&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 21:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504481#M1085179</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-11-17T21:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 Unable to Connect to LAN Devices</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504489#M1085180</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;I wasn't aware that the management interface could not also be used to allow through traffic. I'll connect to a data interface and see what I can do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you foresee any issues if I create a LAN network object and assign it the following IP range that our LAN uses? 192.168.0.0/16&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 21:38:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504489#M1085180</guid>
      <dc:creator>mlandavazo</dc:creator>
      <dc:date>2021-11-17T21:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 Unable to Connect to LAN Devices</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504538#M1085182</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; I removed an ethernet port from the bridge group, connected it to our LAN, and gave it an IP address. From here I can just create the rules you mentioned?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 22:44:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504538#M1085182</guid>
      <dc:creator>mlandavazo</dc:creator>
      <dc:date>2021-11-17T22:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 Unable to Connect to LAN Devices</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504544#M1085184</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Still cannot ping any local devices. I've attached my NAT rule, firewall access rule, and the network object I created for our LAN IP range. Attached pertinent RA VPN rules as well.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 23:59:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-unable-to-connect-to-lan-devices/m-p/4504544#M1085184</guid>
      <dc:creator>mlandavazo</dc:creator>
      <dc:date>2021-11-17T23:59:15Z</dc:date>
    </item>
  </channel>
</rss>

