<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 1120, not passing traffic through ssl vpn in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-1120-not-passing-traffic-through-ssl-vpn/m-p/4866684#M1102260</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1543072"&gt;@mnowicky&lt;/a&gt; you probably need a NAT exemption rule to ensure traffic between the inside networks and the RAVPN pool network is not unintentially translated.&lt;/P&gt;
&lt;P&gt;Example if using FDM to locally manage the FTD:-&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1688401004770.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189349i5340FCDEF6186A94/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RobIngram_0-1688401004770.png" alt="RobIngram_0-1688401004770.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I assume the core switch default route is via the 1120 firewall, so no routing issues?&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jul 2023 16:18:58 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2023-07-03T16:18:58Z</dc:date>
    <item>
      <title>Firepower 1120, not passing traffic through ssl vpn</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-not-passing-traffic-through-ssl-vpn/m-p/4866681#M1102259</link>
      <description>&lt;P&gt;Have an issue with firepower 1120 not passing traffic from ssl vpn to the internal networks. The anyconnect client is able to connect, and provides an IP in the correct pool, however will not route traffic between vpn and internal networks.&lt;/P&gt;&lt;P&gt;The odd thing is that the default gateway assigned to vpn clients is not correct. The correct gateway is 172.30.100.254, while the assigned gateway and subnet mask are wrong, as follows:&lt;/P&gt;&lt;P&gt;subnet: 255.255.0.0&lt;BR /&gt;Gateway: 172.30.0.1&lt;/P&gt;&lt;P&gt;I read that it is correct for the subnet mask to be like that, however something definitely seems wrong. The Firepower appliance is able to ping both the connected client, and hosts in the internal network, but will not pass traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 16:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-not-passing-traffic-through-ssl-vpn/m-p/4866681#M1102259</guid>
      <dc:creator>mnowicky</dc:creator>
      <dc:date>2023-07-03T16:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120, not passing traffic through ssl vpn</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-not-passing-traffic-through-ssl-vpn/m-p/4866684#M1102260</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1543072"&gt;@mnowicky&lt;/a&gt; you probably need a NAT exemption rule to ensure traffic between the inside networks and the RAVPN pool network is not unintentially translated.&lt;/P&gt;
&lt;P&gt;Example if using FDM to locally manage the FTD:-&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1688401004770.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189349i5340FCDEF6186A94/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RobIngram_0-1688401004770.png" alt="RobIngram_0-1688401004770.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I assume the core switch default route is via the 1120 firewall, so no routing issues?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 16:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-not-passing-traffic-through-ssl-vpn/m-p/4866684#M1102260</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-07-03T16:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120, not passing traffic through ssl vpn</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-not-passing-traffic-through-ssl-vpn/m-p/4866700#M1102263</link>
      <description>&lt;P&gt;That was it, thank you so much!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 16:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-not-passing-traffic-through-ssl-vpn/m-p/4866700#M1102263</guid>
      <dc:creator>mnowicky</dc:creator>
      <dc:date>2023-07-03T16:45:47Z</dc:date>
    </item>
  </channel>
</rss>

