<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New WAN outside interface doesn't work! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696630#M1093816</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;At my work we have buy new wan connection.&lt;/P&gt;&lt;P&gt;The topology is&lt;/P&gt;&lt;P&gt;SW_Core -----&amp;gt;FTD----&amp;gt;Outside wan1-2-3&lt;/P&gt;&lt;P&gt;in the SW_Core are 3 vlan:&lt;BR /&gt;WAN1&amp;nbsp;&lt;/P&gt;&lt;P&gt;WAN2&amp;nbsp;&lt;/P&gt;&lt;P&gt;WAN3&amp;nbsp;&lt;/P&gt;&lt;P&gt;From&amp;nbsp; the FTD,&amp;nbsp;&lt;BR /&gt;WAN1 ----&amp;gt; can ping wan1 gw&lt;/P&gt;&lt;P&gt;WAN2 ---&amp;gt; can ping wan2 gw&lt;/P&gt;&lt;P&gt;WAN3 ---&amp;gt; cannot ping wan3 gw.&lt;/P&gt;&lt;P&gt;and i don't now why?&lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 30 Sep 2022 08:54:53 GMT</pubDate>
    <dc:creator>ipv6x</dc:creator>
    <dc:date>2022-09-30T08:54:53Z</dc:date>
    <item>
      <title>New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696630#M1093816</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;At my work we have buy new wan connection.&lt;/P&gt;&lt;P&gt;The topology is&lt;/P&gt;&lt;P&gt;SW_Core -----&amp;gt;FTD----&amp;gt;Outside wan1-2-3&lt;/P&gt;&lt;P&gt;in the SW_Core are 3 vlan:&lt;BR /&gt;WAN1&amp;nbsp;&lt;/P&gt;&lt;P&gt;WAN2&amp;nbsp;&lt;/P&gt;&lt;P&gt;WAN3&amp;nbsp;&lt;/P&gt;&lt;P&gt;From&amp;nbsp; the FTD,&amp;nbsp;&lt;BR /&gt;WAN1 ----&amp;gt; can ping wan1 gw&lt;/P&gt;&lt;P&gt;WAN2 ---&amp;gt; can ping wan2 gw&lt;/P&gt;&lt;P&gt;WAN3 ---&amp;gt; cannot ping wan3 gw.&lt;/P&gt;&lt;P&gt;and i don't now why?&lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 08:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696630#M1093816</guid>
      <dc:creator>ipv6x</dc:creator>
      <dc:date>2022-09-30T08:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696635#M1093818</link>
      <description>&lt;P&gt;I would check the ARP entries on the FTD, and if it shows incomplete I would try to reach out to the ISP. I personally experienced a couple of similar issues where the ISP was adding a VLAN ID tag on the interface connected to the firewall. In that case I had to create the sub-interfaces before I got it to work. Another thing you can try to do is to connect the WAN3 ISP router directly to the firewall and see if that makes any difference, if so, the issue might be related to something missing on the switch.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 09:13:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696635#M1093818</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-30T09:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696655#M1093824</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for the reply, I have a test with my laptop I have put on VLAN wan3 assigned static public IP and it worked. Or in the FTD is another question? I try arp but nothing show on FTD CLI.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 10:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696655#M1093824</guid>
      <dc:creator>ipv6x</dc:creator>
      <dc:date>2022-09-30T10:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696678#M1093827</link>
      <description>&lt;P&gt;Yes but laptop send untag traffic, FTD send tag traffic and SW can't know that tag FTD add.&amp;nbsp;&lt;BR /&gt;here you must sure the tag is match and trunk all new WAN VLAN.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 10:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696678#M1093827</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-09-30T10:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696695#M1093828</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, and all the VLAN WANs have the same tag trk1.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 11:29:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696695#M1093828</guid>
      <dc:creator>ipv6x</dc:creator>
      <dc:date>2022-09-30T11:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696699#M1093829</link>
      <description>&lt;P&gt;Did you connect your laptop directly to the WAN3 router or to a switch port in WAN3 VLAN? if you connected it directly to the WAN3 router then it would mean there is some issues on the WAN3 VLAN switch ports configs. Could you please share the sanitized switch ports configs and a quick draft diagram for review?&lt;/P&gt;
&lt;P&gt;If you have a single physical connection between the FTD and the switch, then the FTD must have the VLAN IDs assigned to its sub-interfaces that match whatever VLAN IDs you configured on the switch. And from the switch ports perspective, the link between the switch and the FTD must be configured in trunk allowing all those three VLANs, and then the switch ports connected to the ISP routers must be configured in access mode and placed into their respective VLAN.&lt;/P&gt;
&lt;P&gt;An exception of the above, would be if you don't configure a VLAN ID on the FTD for one of those three links, and you decide to use the main physical interface for it, then in that case you must configure the native VLAN on the switch trunk link to be the VLAN that is matching whatever you configured on the FTD main interface. For example, you can have WAN1 and 2 configured as sub-interfaces on the FTD, where VLAN tagging is required, and WAN3 configured on the physical interface of the FTD where tagging is not required.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 11:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696699#M1093829</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-30T11:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696712#M1093832</link>
      <description>&lt;P&gt;can you share the config of SW and FTD ?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 12:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696712#M1093832</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-09-30T12:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696728#M1093835</link>
      <description>&lt;P&gt;The configuration is:&lt;/P&gt;&lt;P&gt;FTD-----SWCORE-----WAN1-2-3&lt;/P&gt;&lt;P&gt;FTD have configured 3 interfaces&amp;nbsp;&lt;/P&gt;&lt;P&gt;G0/1 ---&amp;gt; WAN1&lt;/P&gt;&lt;P&gt;G0/2 ---&amp;gt; WAN2&lt;/P&gt;&lt;P&gt;G0/3 ---&amp;gt; WAN 3&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the switch they are connected to port with vlan wan1-2-3 and and they configured like access and tagged with trunk. see the photos&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 12:21:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696728#M1093835</guid>
      <dc:creator>ipv6x</dc:creator>
      <dc:date>2022-09-30T12:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696731#M1093836</link>
      <description>&lt;P&gt;Are you using a dedicate interface on the FTD (as per dia.png file) for each circuit? how did you configure the firewall ports? as sub-interfaces or physical? Based on the dia.png diagram I don't think you need to worry about tagging/trunk at all. You can just configure the firewall physical interfaces and set the switch ports where the firewall interfaces are connected in access mode in their respective VLANs.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 12:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696731#M1093836</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-30T12:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696735#M1093837</link>
      <description>&lt;P&gt;are the issue with WAN-2 (VLAN31)?&lt;BR /&gt;if yes&amp;nbsp;&lt;BR /&gt;then you need to make VLAN UP/UP&amp;nbsp;&lt;BR /&gt;and you can use no autostate to make VLAN UP always&amp;nbsp;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/switches/catalyst-6500-series-switches/41141-188.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/switches/catalyst-6500-series-switches/41141-188.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 12:40:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696735#M1093837</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-09-30T12:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696737#M1093838</link>
      <description>&lt;P&gt;In the FTD i am using physical interfaces and on the sw_core they are configured access port with respective Vlans.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 12:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696737#M1093838</guid>
      <dc:creator>ipv6x</dc:creator>
      <dc:date>2022-09-30T12:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696738#M1093839</link>
      <description>&lt;P&gt;The WAN2 is down because the secondary FTD is upgrading status.&lt;/P&gt;&lt;P&gt;And we have ARUBA switches.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 12:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696738#M1093839</guid>
      <dc:creator>ipv6x</dc:creator>
      <dc:date>2022-09-30T12:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696742#M1093840</link>
      <description>&lt;P&gt;just one more think to check&amp;nbsp;&lt;BR /&gt;you config VLAN in SW with for example port g0/x&amp;nbsp;&lt;BR /&gt;are you sure the FTD is connect to this port ?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 14:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696742#M1093840</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-09-30T14:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696747#M1093841</link>
      <description>&lt;P&gt;Mmm, can't think of why it shouldn't work then. Can you please try to connect your laptop to a switch port in WAN3 VLAN and try to ping the FTD, and ping the laptop from the FTD?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 12:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696747#M1093841</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-30T12:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696761#M1093842</link>
      <description>&lt;P&gt;yes I can ping from the laptop to FTD and vice-versa, also from the laptop I can ping the gw of the isp router, but from FTD I cannot and i don't know why this?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 13:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696761#M1093842</guid>
      <dc:creator>ipv6x</dc:creator>
      <dc:date>2022-09-30T13:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696816#M1093844</link>
      <description>&lt;P&gt;Interesting! Can you please enable ARP debugs on the FTD and try to ping the ISP IP and share the ARP debug output?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 14:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696816#M1093844</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-30T14:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696840#M1093846</link>
      <description>&lt;P&gt;arp-send: arp request built from 10.10.1.3 a03d.6eb8.e77e for 10.10.1.4 at 15:24:04.025&lt;/P&gt;&lt;P&gt;arp-in: response at outside_colt from 10.10.1.3 d4eb.6874.0780 for 10.10.1.4 d4eb.6874.0780 having smac d4eb.6874.0780 dmac ffff.ffff.ffff&lt;BR /&gt;arp-send: arp request built from 10.10.1.3 a03d.6eb8.e77e for 10.10.3 at 15:24:04.905&lt;/P&gt;&lt;P&gt;this 10.10.1.4 is ISP GW&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 15:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696840#M1093846</guid>
      <dc:creator>ipv6x</dc:creator>
      <dc:date>2022-09-30T15:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696912#M1093852</link>
      <description>&lt;P&gt;From the output I see the ARP gets resolved so it should work. I would try to connect the FTD interface directly to the WAN3 router and see if it works, or at least try to clear the ARP table on the router by disconnecting the cable that is connected to the switch.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 17:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696912#M1093852</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-30T17:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696917#M1093853</link>
      <description>&lt;P&gt;Now every this is OK ARP &amp;amp; MAC (as you mention it is correct)&lt;BR /&gt;still there is only one think,&amp;nbsp;&lt;BR /&gt;the source of ping are it FTD interface connect to WAN3 or other interface ?&lt;BR /&gt;please notice this is FTD not router so it behave is different&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 17:30:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4696917#M1093853</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-09-30T17:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: New WAN outside interface doesn't work!</title>
      <link>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4697392#M1093889</link>
      <description>&lt;P&gt;The interface of FTD is connected in core switch because i can't connect directly, the ISP router is in another room CED.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 06:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-wan-outside-interface-doesn-t-work/m-p/4697392#M1093889</guid>
      <dc:creator>ipv6x</dc:creator>
      <dc:date>2022-10-03T06:52:59Z</dc:date>
    </item>
  </channel>
</rss>

