<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure PBR on FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002904#M1108274</link>
    <description>&lt;P&gt;I want to check how is your interface configuration and what zone they are ?&lt;/P&gt;
&lt;P&gt;can you provide relevant config related to interface and PBR, Route&lt;/P&gt;
&lt;P&gt;confirm except the PBR its generally working ?&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jan 2024 22:53:11 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2024-01-22T22:53:11Z</dc:date>
    <item>
      <title>Configure PBR on FMC</title>
      <link>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002716#M1108255</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;I want to configure new implementation to route certain source traffic via different interface. I have 2 OUTSIDE interfaces and 2 interface inside. I want to divide the outbound traffic via WAN and O-365. Load balancer will determine which IP is going to 2 of my inside interface. If user went to outlook or 365 it will follow path interface 1/3 &amp;amp; 1/4 and else, it will go to interface 1/1 &amp;amp; 1/2. current FMC and FTD version is 7.2.5.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zufayri_0-1705942274822.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208194i975CE2759DDD4529/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zufayri_0-1705942274822.png" alt="zufayri_0-1705942274822.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;1/1 - 133.133.1.22&lt;/P&gt;
&lt;P&gt;1/2 - 211.25.10.50 (WAN)&lt;/P&gt;
&lt;P&gt;1/3 - 10.10.11.100&lt;/P&gt;
&lt;P&gt;1/4 - 202.168.100.2(O-365)&lt;/P&gt;
&lt;P&gt;From extended I do:&lt;/P&gt;
&lt;P&gt;Default : src-any, dest-Wan Gateway&lt;/P&gt;
&lt;P&gt;O-365 : src-any, dest-O365 gateway&lt;/P&gt;
&lt;P&gt;PBR :&lt;/P&gt;
&lt;P&gt;Ingress- 1/1 | traffic match - Default | sent through - 1/2&lt;/P&gt;
&lt;P&gt;Ingress- 1/3 | traffic match - O-365 | sent through - 1/4&lt;/P&gt;
&lt;P&gt;Static Route:&lt;/P&gt;
&lt;P&gt;Network-any, Interface 1/1, gateway 1/1, metric 1&lt;/P&gt;
&lt;P&gt;Network-any, Interface 1/3, gateway 1/3, metric 1&lt;/P&gt;
&lt;P&gt;Network-any, Interface 1/2, gateway 1/2, metric 20&lt;/P&gt;
&lt;P&gt;Network-any, Interface 1/4, gateway 1/4, metric 20&lt;/P&gt;
&lt;P&gt;I also configured ECMP for Interface WAN and O-365&lt;/P&gt;
&lt;P&gt;From my setup below is it still need to configure at flexconfig FMC or is my configuration above is enough? Need your expertise to comment my setup.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 17:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002716#M1108255</guid>
      <dc:creator>zufayri</dc:creator>
      <dc:date>2024-01-22T17:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Configure PBR on FMC</title>
      <link>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002718#M1108256</link>
      <description>&lt;P&gt;FMC 7.1 onwards PBR configured using GUI - that is good enough to work :&lt;/P&gt;
&lt;P&gt;check below guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/routing-policy-based.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/routing-policy-based.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 17:24:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002718#M1108256</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-01-22T17:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Configure PBR on FMC</title>
      <link>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002719#M1108257</link>
      <description>&lt;P&gt;I dont think Load balance can load traffic in your case since all traffic pass to FW and from there must flow to correct path.&lt;/P&gt;
&lt;P&gt;So You need flexconfig and config pbr.&lt;/P&gt;
&lt;P&gt;Note:- now fmc support directly fmc no need pbr' it depend on fmc version.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/routing-policy-based.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/routing-policy-based.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 17:28:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002719#M1108257</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-22T17:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Configure PBR on FMC</title>
      <link>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002755#M1108258</link>
      <description>&lt;P&gt;Hi balaji,&lt;/P&gt;
&lt;P&gt;I have follow this guide also but for path monitoring I dont configured as the two ISP have their own traffic. just my concern is from internal, most of the KB and guide show internal only have one interface but this have two. so I dont quite understand how Load balance will split the traffic to both of the internal interface.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 18:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002755#M1108258</guid>
      <dc:creator>zufayri</dc:creator>
      <dc:date>2024-01-22T18:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Configure PBR on FMC</title>
      <link>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002758#M1108259</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So meaning flexconfig also need to be configured? do you have guide to configured flexconfig?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 18:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002758#M1108259</guid>
      <dc:creator>zufayri</dc:creator>
      <dc:date>2024-01-22T18:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Configure PBR on FMC</title>
      <link>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002760#M1108260</link>
      <description>&lt;P&gt;but I see you comment that there your FMC support pbr so no need flexconfig&amp;nbsp;&lt;BR /&gt;for two inside interface&amp;nbsp;&lt;BR /&gt;config two PBR one for each inside interface&amp;nbsp;&lt;BR /&gt;the ACL you can config it with permit any any&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 18:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002760#M1108260</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-22T18:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Configure PBR on FMC</title>
      <link>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002904#M1108274</link>
      <description>&lt;P&gt;I want to check how is your interface configuration and what zone they are ?&lt;/P&gt;
&lt;P&gt;can you provide relevant config related to interface and PBR, Route&lt;/P&gt;
&lt;P&gt;confirm except the PBR its generally working ?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 22:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002904#M1108274</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-01-22T22:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Configure PBR on FMC</title>
      <link>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002995#M1108278</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;both internal zone set as LAN and both ISP zone set as WAN&lt;/P&gt;
&lt;P&gt;This is new implementation so no testing yet as this will be replace sonicwall PBR. most of Sonicwall PBR use PBR src-any, dst-any, interface-internal but gateway is 0.0.0.0, Cisco can do gateway 0.0.0.0 for interface?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 03:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-pbr-on-fmc/m-p/5002995#M1108278</guid>
      <dc:creator>zufayri</dc:creator>
      <dc:date>2024-01-23T03:10:51Z</dc:date>
    </item>
  </channel>
</rss>

