<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web servers issue after migrating from ASA to FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/web-servers-issue-after-migrating-from-asa-to-ftd/m-p/4551918#M1087400</link>
    <description>&lt;P&gt;To rule out if there is an issue caused by FTD, for testing "only" create a bi-directional pre-filter ACL with "fastpath" action with necessary IP address and see if that makes a difference.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Feb 2022 14:32:02 GMT</pubDate>
    <dc:creator>Udupi Krishna.</dc:creator>
    <dc:date>2022-02-14T14:32:02Z</dc:date>
    <item>
      <title>Web servers issue after migrating from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/web-servers-issue-after-migrating-from-asa-to-ftd/m-p/4551692#M1087384</link>
      <description>&lt;P&gt;I migrated the firewall configuration from ASA to FTD context. Firepower is only doing firewall servcies and we do not have any Inspection or web filterign turned on. After the migration the web services stopped working. We are not doing any ssl decryption/encryption on FTD. The F5 loadbalancer which is in front of the firewall is showing ssl communication error with the backend servers which are behind FTD. We checked for all obvious possibilities including policy-map, threat-detection, timeouts but there is nothing that could point to the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the FTD is only providing firewall service why would there be a difference in behaviour compared to ASA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if anybody has faced similar issue or can share some insight it would be helpful&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 07:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/web-servers-issue-after-migrating-from-asa-to-ftd/m-p/4551692#M1087384</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2022-02-14T07:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Web servers issue after migrating from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/web-servers-issue-after-migrating-from-asa-to-ftd/m-p/4551918#M1087400</link>
      <description>&lt;P&gt;To rule out if there is an issue caused by FTD, for testing "only" create a bi-directional pre-filter ACL with "fastpath" action with necessary IP address and see if that makes a difference.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 14:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/web-servers-issue-after-migrating-from-asa-to-ftd/m-p/4551918#M1087400</guid>
      <dc:creator>Udupi Krishna.</dc:creator>
      <dc:date>2022-02-14T14:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Web servers issue after migrating from ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/web-servers-issue-after-migrating-from-asa-to-ftd/m-p/4552094#M1087413</link>
      <description>&lt;P&gt;Personally I never ran into this, but from your description it seems that the F5 is not able to reach to the web servers. I would check the NAT rules if you are using any, and the ACL on the firewall, maybe something basic missing. If all looks good, then I would enable the packet capture on the external interface connected to the F5, as well as on the internal connected to the web servers and check the flows. I would also run packet tracer to simulate the flow and see why it would fail.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 17:56:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/web-servers-issue-after-migrating-from-asa-to-ftd/m-p/4552094#M1087413</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-02-14T17:56:35Z</dc:date>
    </item>
  </channel>
</rss>

