<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FPR 3105- Migrating 2 Subnets in same zone in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233310#M1118010</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DIA.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/235299iE4BAFE133477B170/image-size/large?v=v2&amp;amp;px=999" role="button" title="DIA.png" alt="DIA.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2024 09:04:41 GMT</pubDate>
    <dc:creator>ManadarDesai2895</dc:creator>
    <dc:date>2024-12-06T09:04:41Z</dc:date>
    <item>
      <title>FPR 3105- Migrating 2 Subnets in same zone</title>
      <link>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233268#M1118008</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;&lt;P&gt;We have 2 server subnets "vlan 130 -10.72.12.0/25" &amp;amp;&amp;nbsp; "vlan 140 -10.72.12.128/25" configured as SVIs on L3 switch. Both these vlans are working as a part of inter-vlan routing on L3 switch without any restrictions. Now as a part Segmentation project we need to configure L3 interfaces on FPR-3105(FTD image) interfaces to isolate the unwanted access from other vlans from Core Switch.&lt;/P&gt;&lt;P&gt;As we don't have exact communication required between servers configured on these 2 server vlans, can we create 2 different interface for the routing &amp;amp; keep them assigned under same security zone as "SRV". Will this enable these subnets to talk with each other without dropping any traffic between them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 07:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233268#M1118008</guid>
      <dc:creator>ManadarDesai2895</dc:creator>
      <dc:date>2024-12-06T07:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: FPR 3105- Migrating 2 Subnets in same zone</title>
      <link>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233279#M1118009</link>
      <description>&lt;P&gt;Providing network diagrams of how the network is now and what you are trying to achieve will help us understand the situation better.&lt;/P&gt;
&lt;P&gt;That being said, You can add the VLAN 130 and 140 to sub-interfaces on the FTD3105 and both of these can be members of the same security zone.&amp;nbsp; you would still need to allow the traffic between these two VLANs in access rules, this is not allowed by default even though they are in the same security zone.&lt;/P&gt;
&lt;P&gt;To identify what ports are required between the server zones and from client to server zone for that matter, you can implement a firewall analyzer software such as AlgoSec and send firewall connection syslogs to it.&amp;nbsp; It will analyze the connections and provide information on how to start tightening up access rules that are too general.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 08:06:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233279#M1118009</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-12-06T08:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: FPR 3105- Migrating 2 Subnets in same zone</title>
      <link>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233310#M1118010</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DIA.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/235299iE4BAFE133477B170/image-size/large?v=v2&amp;amp;px=999" role="button" title="DIA.png" alt="DIA.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 09:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233310#M1118010</guid>
      <dc:creator>ManadarDesai2895</dc:creator>
      <dc:date>2024-12-06T09:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: FPR 3105- Migrating 2 Subnets in same zone</title>
      <link>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233312#M1118011</link>
      <description>&lt;P&gt;FIND DIAGRAM&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 09:05:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233312#M1118011</guid>
      <dc:creator>ManadarDesai2895</dc:creator>
      <dc:date>2024-12-06T09:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: FPR 3105- Migrating 2 Subnets in same zone</title>
      <link>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233323#M1118012</link>
      <description>&lt;P&gt;Then the solution I provided in my previous post is correct.&amp;nbsp; The interfaces on the FTD can be in the same security zone but you still need to allow communication between the networks in access rules.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 09:23:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-3105-migrating-2-subnets-in-same-zone/m-p/5233323#M1118012</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-12-06T09:23:14Z</dc:date>
    </item>
  </channel>
</rss>

