<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 1010 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635195#M1091091</link>
    <description>&lt;P&gt;You must make sure that the both VLAN in same Zone.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jun 2022 18:33:18 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-06-20T18:33:18Z</dc:date>
    <item>
      <title>Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4634912#M1091074</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have the following situation. We have at work a subnet (192.168.0.0/24)&amp;nbsp; used by all equipment ( wifi devices, mng for switches, printers etc ) . We have a cisco firepower 1010 and a cisco sw. I created on ftd 1010 on interface Ethernet1/5 two subinterfaces ( vlan 10 with 192.168.10.0/24 subnet and vlan 20 with 192.168.20.0/24 subnet ) . I connected the ftd 1010 port 5 to the switch and the port on the switch i've configured it in trunk mode with vlan 10,20 . I've connected a pc in switch and set that port in access vlan 10 . The problem is that from that PC ( 192.168.10.20 ) i can ping the gateway but cannot ping a pc from the 192.168.0.0/24 subnet or viceversa. I've configured object "new_subnet" with 192.168.10.0/24 and policies where i've set allow from 192.168.0.0/24 subnet to 192.168.10.0/24 subnet and viceversa and still doesent work.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 12:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4634912#M1091074</guid>
      <dc:creator>IgnatAndrei</dc:creator>
      <dc:date>2022-06-20T12:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4634971#M1091075</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1368951"&gt;@IgnatAndrei&lt;/a&gt; it's possibly a NAT issue, assuming you've configured NAT to allow these networks to access the internet.&lt;/P&gt;
&lt;P&gt;You will need to create NAT exemption rules between these networks, to ensure traffic is not translated. These NAT rules would be above your Auto NAT rules used for internet access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In addition, you can run packet-tracer, this will provide more information as to where the issue lies.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 12:51:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4634971#M1091075</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-06-20T12:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4634984#M1091077</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;thx for the answer. Unfortunately i`m newbie with cisco firewalls, can you please guide me ? I've made a pic with the NAT menu. I don`t also understand what has to do NAT with inter-vlan routing. I cannot access the other vlan locally , i don't what to acces it from internet. I think the problem may be with the access list. But i've created rule and still doesent work.&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 13:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4634984#M1091077</guid>
      <dc:creator>IgnatAndrei</dc:creator>
      <dc:date>2022-06-20T13:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4634993#M1091080</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1368951"&gt;@IgnatAndrei&lt;/a&gt; because traffic from one VLAN would be translated behind the FTD interface, unless configure not to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot see your rules behind to determine if they are conflicting, but you need to define Manual NAT rules as per the example below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 710px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154119iAF6D68FD46D2413D/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this rule ensures traffic between vlan5 and vlan6 networks are not translated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Running packet-tracer as requested, would confirm the packet flow through the firewall and confirm my suspicion.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 13:31:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4634993#M1091080</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-06-20T13:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635007#M1091082</link>
      <description>&lt;P&gt;I`ve attached some pictures to better understand the router configuration.&lt;/P&gt;&lt;P&gt;This in my subinterface configuration :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="interface5.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154124i53161AFD4C9A7DC9/image-size/large?v=v2&amp;amp;px=999" role="button" title="interface5.png" alt="interface5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and this is subinterface config:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imprimante_subinterface.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154122i0FECD8FA04FE66A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="imprimante_subinterface.png" alt="imprimante_subinterface.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eq_management_subinterface.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154123i783EEB5C8D00F9AA/image-size/large?v=v2&amp;amp;px=999" role="button" title="eq_management_subinterface.png" alt="eq_management_subinterface.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I want that from wifi_lan to access imprimante subnet. This is what i have when select add nat rule&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nat rule.png" style="width: 799px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154125i69658A724FD8D387/image-size/large?v=v2&amp;amp;px=999" role="button" title="nat rule.png" alt="nat rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I don`t know how to use packet tracer from cli&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 13:58:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635007#M1091082</guid>
      <dc:creator>IgnatAndrei</dc:creator>
      <dc:date>2022-06-20T13:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635011#M1091084</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1368951"&gt;@IgnatAndrei&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Manual NAT/ Static&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source interface: imprimante&lt;/P&gt;
&lt;P&gt;Original source: 192.168.10.0&lt;/P&gt;
&lt;P&gt;Translated source: 192.168.10.0&lt;/P&gt;
&lt;P&gt;Destination interface: eq_management&lt;/P&gt;
&lt;P&gt;Original destination: 192.168.20.0&lt;/P&gt;
&lt;P&gt;Translated destination: 192.168.20.0&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 14:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635011#M1091084</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-06-20T14:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635039#M1091085</link>
      <description>&lt;P&gt;I will ckeck tomorrow and see if it works. I also have other subnets configured on ethernet 2,3,4 on firepower and i cannot see any rule in nat and i can ping from one subnet to another. This rule is applyed only whem you create subinterfaces or is the default behavior that you have to implement ? If is that, then why other subnets can ping each other without any nat rule ? Thx&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 14:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635039#M1091085</guid>
      <dc:creator>IgnatAndrei</dc:creator>
      <dc:date>2022-06-20T14:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635195#M1091091</link>
      <description>&lt;P&gt;You must make sure that the both VLAN in same Zone.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 18:33:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635195#M1091091</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-20T18:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635593#M1091104</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;they are in the same Security zone and it does not work.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;i want from wifi to imprimante . But i'm kind off affraid to create the rule to not break somethink...&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 08:56:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635593#M1091104</guid>
      <dc:creator>IgnatAndrei</dc:creator>
      <dc:date>2022-06-21T08:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635614#M1091106</link>
      <description>&lt;P&gt;I mean is there a way to schedule a reboot if i make the rule and deploy and if something went wrong to reboot and perform a rollback to initial configuration ?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 09:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4635614#M1091106</guid>
      <dc:creator>IgnatAndrei</dc:creator>
      <dc:date>2022-06-21T09:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4637546#M1091211</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Any help please ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 13:42:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010/m-p/4637546#M1091211</guid>
      <dc:creator>IgnatAndrei</dc:creator>
      <dc:date>2022-06-23T13:42:53Z</dc:date>
    </item>
  </channel>
</rss>

