<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internet Routing FTD 2120 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5162050#M1115127</link>
    <description>&lt;P&gt;you can do policy routing&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2021/04/18/ftd-policy-based-routing/" target="_blank"&gt;https://integratingit.wordpress.com/2021/04/18/ftd-policy-based-routing/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;so that only the&amp;nbsp; visitor subnet will be policy routed to the new circuit.. see example&lt;/P&gt;
&lt;P&gt;7.3 and 7.4 have added more sdwan type of capabilities for better control etc.. but plain and simple policy routing will work if you are on older versions..&lt;/P&gt;</description>
    <pubDate>Sat, 17 Aug 2024 07:50:17 GMT</pubDate>
    <dc:creator>ccieexpert</dc:creator>
    <dc:date>2024-08-17T07:50:17Z</dc:date>
    <item>
      <title>Internet Routing FTD 2120</title>
      <link>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5161963#M1115126</link>
      <description>&lt;P&gt;I have a FMC managing two 2120 devices.&amp;nbsp; They are connected to our SD Wand circuit.&amp;nbsp; We recently purchased a standalone internet circuit.&amp;nbsp; I am trying to see if the visitor traffic on the network can be routed through the firewall and out the standalone circuit and not go through the SD wan.&amp;nbsp; I have created a sub interface and assigned one of the interfaces to it.&amp;nbsp; The traffic from the network comes to the core and a Nat is created to route it out to the stand alone.&amp;nbsp; Does the interface need a statis IP to route the traffic out or can the interface do a layer 2 passthrough to let it out?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 23:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5161963#M1115126</guid>
      <dc:creator>Darren Thompson</dc:creator>
      <dc:date>2024-08-16T23:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Routing FTD 2120</title>
      <link>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5162050#M1115127</link>
      <description>&lt;P&gt;you can do policy routing&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2021/04/18/ftd-policy-based-routing/" target="_blank"&gt;https://integratingit.wordpress.com/2021/04/18/ftd-policy-based-routing/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;so that only the&amp;nbsp; visitor subnet will be policy routed to the new circuit.. see example&lt;/P&gt;
&lt;P&gt;7.3 and 7.4 have added more sdwan type of capabilities for better control etc.. but plain and simple policy routing will work if you are on older versions..&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 07:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5162050#M1115127</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-08-17T07:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Routing FTD 2120</title>
      <link>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5162058#M1115128</link>
      <description>&lt;P&gt;To answer we need more info.&lt;/P&gt;
&lt;P&gt;You config fw with sdwan' usually sdwan use igp with device connect to service vpn' but here you use default route in fw to forward traffic to sdwan vedge router?&lt;/P&gt;
&lt;P&gt;That I think why you ask' to forward traffic to internet you need additional defualt route and this make two defualt route in FTD and not work.&lt;/P&gt;
&lt;P&gt;What ypu need is using IGP between ftd and sdwan to learn prefix of all other sdwan branches then config defualt route in ftd toward internet ISP.&lt;/P&gt;
&lt;P&gt;It sdwan issue more than FW issue&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 09:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5162058#M1115128</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-17T09:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Routing FTD 2120</title>
      <link>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5162289#M1115145</link>
      <description>&lt;P&gt;Please dont get confused with confusing statements &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;if i understand SDWAN is done by a ISP router or another router/firewall that is in front of your firewall. So essentially your firewall has a default route to this SDWAN router firewall/router and that provides the load balancing / sharing for existing internet circuits ? right ?&lt;/P&gt;
&lt;P&gt;And you are getting another internet circuit ?&lt;/P&gt;
&lt;P&gt;If this is all true, then please follow my instructions earlier with policy routing and that should just work fine ...&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 09:11:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5162289#M1115145</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-08-18T09:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Routing FTD 2120</title>
      <link>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5162291#M1115146</link>
      <description>&lt;P&gt;please make review&amp;nbsp;&lt;BR /&gt;how other SDWAN know there is internet ISP connect to FW and need to forward traffic to FW ??&lt;/P&gt;
&lt;P&gt;PBR in FTD make other SDWAN edge routers know to access internet send traffic to FW !!!!!&lt;/P&gt;
&lt;P&gt;pbr only work if all visitor subnet direct connect to FW.&lt;/P&gt;
&lt;P&gt;please answer this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 09:54:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-routing-ftd-2120/m-p/5162291#M1115146</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-18T09:54:10Z</dc:date>
    </item>
  </channel>
</rss>

