<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FTD - Snort blocking access from one subnet to outside inter in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039763#M1109879</link>
    <description>&lt;P&gt;Sure. Also I blurred IP but there is a IP of a gateway from out ISP. I found only this with Lookup phase&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2024 14:37:46 GMT</pubDate>
    <dc:creator>NetworkPitu</dc:creator>
    <dc:date>2024-03-14T14:37:46Z</dc:date>
    <item>
      <title>Cisco FTD - Snort blocking access from one subnet to outside interface</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039415#M1109860</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;in company we have Cisco Firepower 1140 to this we have connected Cisco ISR and switch. We created new subnet for customer SDWAN to get access to internet from our ISP. So everything localy works. From ISR I can ping local IP address of our FTD with source of this new subnet but to outside like 8.8.8.8 I have issue. Basically there is no ping from this subnet to network even if we have other our subnets configured in same way and they are working fine. I added ACL rule to allow/trust traffic from this subnet to outside to all IPs and ports. Still same issue&lt;/P&gt;&lt;P&gt;Our FTDs are managed by FMC. In there in Packet Tracer we have error/deny by Snort (I attached screenshot from this part)&lt;/P&gt;&lt;P&gt;To be honest I am trying to solve it like a week now and I really need urgent help. I will be very&amp;nbsp;grateful for any tips and solutions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 10:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039415#M1109860</guid>
      <dc:creator>NetworkPitu</dc:creator>
      <dc:date>2024-03-14T10:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039448#M1109861</link>
      <description>&lt;P&gt;Show access-list&lt;/P&gt;
&lt;P&gt;The packet-tracer show rule ID that drop packet&lt;/P&gt;
&lt;P&gt;Check this rule ID&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 10:48:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039448#M1109861</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-14T10:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039495#M1109865</link>
      <description>&lt;P&gt;Yes, I see this:&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;access-list CSM_FW_ACL_ line &lt;/SPAN&gt;&lt;SPAN&gt;82&lt;/SPAN&gt;&lt;SPAN&gt; remark rule-id 268434432: ACCESS POLICY: Global_Policy - Default&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;access-list CSM_FW_ACL_ line &lt;/SPAN&gt;&lt;SPAN&gt;83&lt;/SPAN&gt;&lt;SPAN&gt; remark rule-id 268434432: L4 RULE: DEFAULT ACTION RULE&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;access-list CSM_FW_ACL_ line &lt;/SPAN&gt;&lt;SPAN&gt;84&lt;/SPAN&gt;&lt;SPAN&gt; advanced deny ip any any rule-id &lt;/SPAN&gt;&lt;SPAN&gt;268434432&lt;/SPAN&gt; &lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;hitcnt=0&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt; &lt;SPAN&gt;0x97aa021a&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;So thats why it is blocking. So how can I allow it? Even if I have in ACL rule to allow this subnet to internet?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 14 Mar 2024 11:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039495#M1109865</guid>
      <dc:creator>NetworkPitu</dc:creator>
      <dc:date>2024-03-14T11:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039503#M1109866</link>
      <description>&lt;P&gt;You mention that you add ACL, can I see the ACL in FTD&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 11:42:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039503#M1109866</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-14T11:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039509#M1109868</link>
      <description>&lt;P&gt;Sure. For security I blurred name of rule and second one is object with this new subnet.&lt;/P&gt;&lt;P&gt;Also I selected action to trust but I tested it with allow&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 11:47:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039509#M1109868</guid>
      <dc:creator>NetworkPitu</dc:creator>
      <dc:date>2024-03-14T11:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039555#M1109869</link>
      <description>&lt;P&gt;For ACL order I will make double check&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But also what I notice is zone&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The drop packey pass from zone2 to zone2 ? Can you also make double check this point.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 12:25:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039555#M1109869</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-14T12:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039572#M1109871</link>
      <description>&lt;P&gt;Sorry, where you notice zone2? I checked screenshots and I cannot find them. We have zone "inside" and "outside" as our main zones in network&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 12:35:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039572#M1109871</guid>
      <dc:creator>NetworkPitu</dc:creator>
      <dc:date>2024-03-14T12:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039663#M1109873</link>
      <description>&lt;P&gt;aa ok, found it in Packet Tracer. To be honest I am not sure why even if we don't have zone called "zone2"&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 13:37:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039663#M1109873</guid>
      <dc:creator>NetworkPitu</dc:creator>
      <dc:date>2024-03-14T13:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039730#M1109877</link>
      <description>&lt;P&gt;can you share the lookup phase of packet-tracer&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 14:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039730#M1109877</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-14T14:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039763#M1109879</link>
      <description>&lt;P&gt;Sure. Also I blurred IP but there is a IP of a gateway from out ISP. I found only this with Lookup phase&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 14:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039763#M1109879</guid>
      <dc:creator>NetworkPitu</dc:creator>
      <dc:date>2024-03-14T14:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039791#M1109880</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-14 105322.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212546i4CF2EBF05A702B06/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-03-14 105322.png" alt="Screenshot 2024-03-14 105322.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 14:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5039791#M1109880</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-14T14:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5040496#M1109909</link>
      <description>&lt;P&gt;ohh ok got it but I don't know why it is to same zone (internet) even if it is configured correctly on ISR. Maybe you know what to check why it is happened?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 08:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5040496#M1109909</guid>
      <dc:creator>NetworkPitu</dc:creator>
      <dc:date>2024-03-15T08:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - Snort blocking access from one subnet to outside inter</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5041267#M1109945</link>
      <description>&lt;P&gt;can I see how you config the packet-tracer&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 09:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-snort-blocking-access-from-one-subnet-to-outside/m-p/5041267#M1109945</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-16T09:47:40Z</dc:date>
    </item>
  </channel>
</rss>

