<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: POLICY-BASED ROUTING- FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/policy-based-routing-ftd/m-p/5284404#M1120701</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1556185"&gt;@fmugambi&lt;/a&gt; what have you configured, can you provide screenshots.&lt;/P&gt;
&lt;P&gt;Run packet-tracer from the CLI to simulate the traffic flow, it will show all the steps and indicate where the issue is.&lt;/P&gt;
&lt;P&gt;Check your NAT configuration to ensure traffic is not unintentially translated. The packet-tracer output would confirm which NAT rule traffic matched (if any).&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2025 18:04:41 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2025-04-23T18:04:41Z</dc:date>
    <item>
      <title>POLICY-BASED ROUTING- FTD</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-ftd/m-p/5284371#M1120700</link>
      <description>&lt;P&gt;Hello Team,&lt;BR /&gt;I have topology as attached,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fmugambi_0-1745423185905.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244010i582614978191D1C1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fmugambi_0-1745423185905.png" alt="fmugambi_0-1745423185905.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I have introduced another interface on the ftd [172.16.40.25] . this is where have configured the new tunnel to the branch site.&lt;/P&gt;
&lt;P&gt;on the asa have natted 41.206.58.2&amp;gt; 172.16.40.25 on 4500/500 services.&lt;/P&gt;
&lt;P&gt;i then use the asa outside interface as peer on the branch site, ideally doing port-forwarding.&lt;/P&gt;
&lt;P&gt;the challenge is the branch site vpn only comes up when i ammend the default route to 0.0.0.0/0 172.16.40.29, which is not what i want. i want the default route remain 0.0.0.0/0 102.6.239.9 , then have a policy-route for remote branch traffic/ response to the branch peer, for the vpn tunnel to come up.&lt;/P&gt;
&lt;P&gt;when i capture traffic from branch office on the asa, am able to see traffic , but no response traffic from ftd.&lt;/P&gt;
&lt;P&gt;i have created a pbr on ftd saying traffic destined for branch office with source as ftd [172.16.40.25] be sent to next hop 172.16.40.29.&lt;/P&gt;
&lt;P&gt;but using capture i see this traffic trying to flow over the dmz-ipsec zone.&lt;/P&gt;
&lt;P&gt;what could i be missing.&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 15:52:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-ftd/m-p/5284371#M1120700</guid>
      <dc:creator>fmugambi</dc:creator>
      <dc:date>2025-04-23T15:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: POLICY-BASED ROUTING- FTD</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-ftd/m-p/5284404#M1120701</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1556185"&gt;@fmugambi&lt;/a&gt; what have you configured, can you provide screenshots.&lt;/P&gt;
&lt;P&gt;Run packet-tracer from the CLI to simulate the traffic flow, it will show all the steps and indicate where the issue is.&lt;/P&gt;
&lt;P&gt;Check your NAT configuration to ensure traffic is not unintentially translated. The packet-tracer output would confirm which NAT rule traffic matched (if any).&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 18:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-ftd/m-p/5284404#M1120701</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-04-23T18:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: POLICY-BASED ROUTING- FTD</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-ftd/m-p/5284584#M1120707</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fmugambi_0-1745471919203.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244052i3BB746F52BE5781B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fmugambi_0-1745471919203.png" alt="fmugambi_0-1745471919203.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fmugambi_1-1745471950271.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244053i8BE8C5C75E9E262B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fmugambi_1-1745471950271.png" alt="fmugambi_1-1745471950271.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;ICOLO-FTDv# packet-tracer input Icolo_to_GCP udp 172.16.40.25 500 34.242.85.1 $&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Elapsed time: 40140 ns&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x14c15c128f90, priority=1, domain=permit, deny=false&lt;BR /&gt;hits=1046943, user_data=0x0, cs_id=0x0, l3_type=0x8&lt;BR /&gt;src mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt;dst mac=0000.0000.0000, mask=0100.0000.0000&lt;BR /&gt;input_ifc=Icolo_to_GCP, output_ifc=any&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: PBR-LOOKUP&lt;BR /&gt;Subtype: policy-route&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Elapsed time: 76266 ns&lt;BR /&gt;Config:&lt;BR /&gt;route-map FMC_GENERATED_PBR_1744811918364 permit 5&lt;BR /&gt;match ip address FTDv-To-GCP&lt;BR /&gt;set ip next-hop 172.16.40.29&lt;BR /&gt;Additional Information:&lt;BR /&gt;Matched route-map FMC_GENERATED_PBR_1744811918364, sequence 5, permit&lt;BR /&gt;Found next-hop 172.16.40.29 using egress ifc Icolo_to_GCP&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Elapsed time: 21742 ns&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x14c15c138a30, priority=501, domain=permit, deny=true&lt;BR /&gt;hits=3066, user_data=0x7, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;src ip/id=172.16.40.25, mask=255.255.255.255, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0, nsg_id=none&lt;BR /&gt;input_ifc=Icolo_to_GCP(vrfid:0), output_ifc=any&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: Icolo_to_GCP(vrfid:0)&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: Icolo_to_GCP(vrfid:0)&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Time Taken: 138148 ns&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x0000562c256fd518 flow (NA)/NA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 05:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-ftd/m-p/5284584#M1120707</guid>
      <dc:creator>fmugambi</dc:creator>
      <dc:date>2025-04-24T05:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: POLICY-BASED ROUTING- FTD</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-routing-ftd/m-p/5285877#M1120776</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;was this helpful?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 09:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-routing-ftd/m-p/5285877#M1120776</guid>
      <dc:creator>fmugambi</dc:creator>
      <dc:date>2025-04-28T09:52:35Z</dc:date>
    </item>
  </channel>
</rss>

