<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 1010 NAT configuration for ISP Router WAN STATIC IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913569#M1103869</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I share screenshots of my 1010 conf:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf1.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195553i92AE6BD5A3828D70/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf1.png" alt="Conf1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195554i7F848C49B5D9A191/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf2.png" alt="Conf2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf6.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195555i2A8B2BA18B9BD5C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf6.png" alt="Conf6.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf3.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195556i89162932011F7FAD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf3.png" alt="Conf3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf4.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195557i58B524A04E5CB011/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf4.png" alt="Conf4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf5.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195558iB7F272B3D3A78B42/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf5.png" alt="Conf5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; Thnak you&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;Antonio&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Aug 2023 07:58:14 GMT</pubDate>
    <dc:creator>reinventy</dc:creator>
    <dc:date>2023-08-29T07:58:14Z</dc:date>
    <item>
      <title>Firepower 1010 NAT configuration for ISP Router WAN STATIC IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913482#M1103863</link>
      <description>&lt;P&gt;Hello to all&amp;nbsp;&lt;/P&gt;&lt;P&gt;and thank you very much in advance for help and suggestion.&lt;/P&gt;&lt;P&gt;I have to configure my Firepower 1010 to allow external users (internet) to reach my internal server where the website and cpanel services reside.&lt;/P&gt;&lt;P&gt;My static ip is managed by the ISP router, the router is a TIM HUB+.&lt;/P&gt;&lt;P&gt;My network is set up like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISP router (WAN IP 80.104.xxx.xxx reachable from the internet) and&amp;nbsp; IP 192.168.0.10 (net 255.255.255.0)&lt;/P&gt;&lt;P&gt;The ISP router forwards all incoming calls to the DMZ 192.168.0.11 which is the outside interface of the Cisco Firepower 1010.&lt;/P&gt;&lt;P&gt;The internal server is connected to inside_3 interface of the Firepower 1010 and has a static IP 192.168.2.25.&lt;/P&gt;&lt;P&gt;I created following objects:&lt;BR /&gt;4 WebserverPrivate HOST 192.168.2.25&lt;BR /&gt;5 WebserverPublic HOST 80.104.xxx.xxx&lt;/P&gt;&lt;P&gt;I added a new NAT policy along the lines of:&lt;/P&gt;&lt;P&gt;Original Packet&lt;BR /&gt;Interface = outside&lt;BR /&gt;Source IP = any-ipv4&lt;BR /&gt;Destination IP = &amp;lt;WebServerPublic&amp;gt;&lt;BR /&gt;Source Port = Any&lt;BR /&gt;Destination Port = HTTPS (or ANY or 2087 for cpanel)&lt;/P&gt;&lt;P&gt;Destination Packet&lt;BR /&gt;Interface = inside_3&lt;BR /&gt;Source IP = any-ipv4&lt;BR /&gt;Destination IP = &amp;lt;WebServerPrivate&amp;gt;&lt;BR /&gt;Source Port = Any&lt;BR /&gt;Destination Port = HTTPS (or ANY or 2087 for cpanel)&lt;/P&gt;&lt;P&gt;Then I added&amp;nbsp; a Access Rule as follow:&lt;/P&gt;&lt;P&gt;Source&lt;BR /&gt;Zones = outside_zone&lt;BR /&gt;Networks = ANY&lt;BR /&gt;Ports = ANY&lt;BR /&gt;Destination&lt;BR /&gt;Zone = inside_zone&lt;BR /&gt;Networks = &amp;lt;WebServerPrivate&amp;gt;&lt;BR /&gt;Ports = HTTPS (or ANY or 2087 for cpanel)&lt;/P&gt;&lt;P&gt;Unfortunately this configuration do not work, the server remain unreachable and unpingable.....&lt;/P&gt;&lt;P&gt;I tried a lot of configurations as NAT but the result is always the same...... external connections are blocked and the server cannot be reachable.&lt;/P&gt;&lt;P&gt;I also tried to change ISP router configuration trying before to forward to DMZ &amp;gt;192.168.0.11 and also trying to use port forwarding to specifics port to Firepower (outside interface192.168.0.11) but nothing.....&lt;/P&gt;&lt;P&gt;Thank you very much for suggestion....&lt;/P&gt;&lt;P&gt;Antonio&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 06:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913482#M1103863</guid>
      <dc:creator>reinventy</dc:creator>
      <dc:date>2023-08-29T06:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 NAT configuration for ISP Router WAN STATIC IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913487#M1103865</link>
      <description>&lt;LI-CODE lang="markup"&gt;ISP router (WAN IP 80.104.xxx.xxx reachable from the internet) and  IP 192.168.0.10 (net 255.255.255.0)&lt;/LI-CODE&gt;
&lt;P&gt;I assume below assumption your setup ?&lt;/P&gt;
&lt;P&gt;Internet (ISP) --Router---FW 1010 - Inside&lt;/P&gt;
&lt;P&gt;So your Router Doing NAT ? then you need to have routing in Place to reach Local Web Server&lt;/P&gt;
&lt;P&gt;Either you need to do Double NAT on Firepower or you need to Configure on Router do to NAT&lt;/P&gt;
&lt;P&gt;see example of NAT works :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212702-configure-and-verify-nat-on-ftd.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212702-configure-and-verify-nat-on-ftd.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;what Router and what options you have on the Router ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 06:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913487#M1103865</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-08-29T06:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 NAT configuration for ISP Router WAN STATIC IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913518#M1103866</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1581771"&gt;@reinventy&lt;/a&gt; You need to translate behind the outside interface (not the public IP address of&amp;nbsp;WebServerPublic thats configured on the ISP router that FTD knows nothing about).&lt;/P&gt;
&lt;P&gt;Assuming the ISP router is natting the required ports to the FTD outside interface, the example below should work. Just define the correct ports and source address object (WebServerPrivate).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="020820_1405_ftdconfigur17.png" style="width: 555px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195550i88E1F5BD7BD39056/image-dimensions/555x442?v=v2" width="555" height="442" role="button" title="020820_1405_ftdconfigur17.png" alt="020820_1405_ftdconfigur17.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 07:08:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913518#M1103866</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-29T07:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 NAT configuration for ISP Router WAN STATIC IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913520#M1103867</link>
      <description>&lt;P&gt;Good morning BB and thank you very much for your help.&lt;/P&gt;&lt;P&gt;Yes my configuration is Internet ISP Router (NAT activated, IPV4 80.104.xxx.xxx (static IP), Gateway 192.168.100.1, Server DNS&amp;nbsp;&lt;SPAN&gt;85.38.28.5,85.38.28.4 &amp;gt; Firepower 1010 &amp;gt; Inside. Router is a TIM HUB+ (Technicolor AGMY2020 Serial CP2050RAJ62 Software Version 19.4) with following configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DHCP activated&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Network Addresses 192.168.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DNS Server 192.168.0.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Router address 192.168.0.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DMZ activated &amp;gt; 192.168.2.10 (Firepower)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But no option to setup or modify NAT.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Antonio&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 07:09:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913520#M1103867</guid>
      <dc:creator>reinventy</dc:creator>
      <dc:date>2023-08-29T07:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 NAT configuration for ISP Router WAN STATIC IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913532#M1103868</link>
      <description>&lt;P&gt;Thank you very much Rob,&lt;/P&gt;&lt;P&gt;I tried also this NAT configuration but server still remain unreachable.....&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;Antonio&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 07:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913532#M1103868</guid>
      <dc:creator>reinventy</dc:creator>
      <dc:date>2023-08-29T07:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 NAT configuration for ISP Router WAN STATIC IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913569#M1103869</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I share screenshots of my 1010 conf:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf1.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195553i92AE6BD5A3828D70/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf1.png" alt="Conf1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195554i7F848C49B5D9A191/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf2.png" alt="Conf2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf6.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195555i2A8B2BA18B9BD5C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf6.png" alt="Conf6.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf3.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195556i89162932011F7FAD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf3.png" alt="Conf3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf4.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195557i58B524A04E5CB011/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf4.png" alt="Conf4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Conf5.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195558iB7F272B3D3A78B42/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Conf5.png" alt="Conf5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; Thnak you&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;Antonio&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 07:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913569#M1103869</guid>
      <dc:creator>reinventy</dc:creator>
      <dc:date>2023-08-29T07:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 NAT configuration for ISP Router WAN STATIC IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913603#M1103870</link>
      <description>&lt;P&gt;And router cnf:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RouterCnf.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195559iACD139EEE4A760DF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RouterCnf.png" alt="RouterCnf.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RouterCnf2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195560i84CBBB271D0776B9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RouterCnf2.png" alt="RouterCnf2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RouterCnf3.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195561i8EDA50EBBADF2AFB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RouterCnf3.png" alt="RouterCnf3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 07:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913603#M1103870</guid>
      <dc:creator>reinventy</dc:creator>
      <dc:date>2023-08-29T07:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 NAT configuration for ISP Router WAN STATIC IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913651#M1103872</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1581771"&gt;@reinventy&lt;/a&gt; run packet-tracer from the CLI and confirm what NAT rule is being matched, provide the output. Example:&lt;/P&gt;
&lt;P&gt;packet-tracer input outside tcp 5.5.5.5 3000 80.104.xxx.xxx 443&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 08:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-nat-configuration-for-isp-router-wan-static-ip/m-p/4913651#M1103872</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-08-29T08:56:07Z</dc:date>
    </item>
  </channel>
</rss>

