<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD 1120 Remote Access VPN issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5287056#M1120838</link>
    <description>&lt;P&gt;Yes I've setup self signed cert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;V/R,&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;</description>
    <pubDate>Fri, 02 May 2025 00:10:23 GMT</pubDate>
    <dc:creator>d-satbir</dc:creator>
    <dc:date>2025-05-02T00:10:23Z</dc:date>
    <item>
      <title>FTD 1120 Remote Access VPN issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5286433#M1120806</link>
      <description>&lt;P&gt;I've setup Remote Access VPN on FTD 1120 using FDM method. I've used the following link to configure the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/212424-anyconnect-remote-access-vpn-configurati.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/212424-anyconnect-remote-access-vpn-configurati.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The issue I'm experiencing is that I can't ping the firewall's wan interface from outside of network and also I can't connect to the VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;WAN connection from ISP is directly connected to the FTD and I've configured the static IP address on the outside interface. I've also configured the DNS entry for the VPN on GoDaddy DNS page.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure if I'm missing anything here.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 03:43:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5286433#M1120806</guid>
      <dc:creator>d-satbir</dc:creator>
      <dc:date>2025-04-30T03:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120 Remote Access VPN issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5286469#M1120809</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1839078"&gt;@d-satbir&lt;/a&gt; you should be able to ping the FTD's interface as default. Is there a device in front of the FTD that could block ICMP or SSL/IPSec?&lt;/P&gt;
&lt;P&gt;Can you ping from the FTD CLI to the internet?&lt;/P&gt;
&lt;P&gt;Is routing setup correctly via the outside interface?&lt;/P&gt;
&lt;P&gt;Can you access the internet through the FTD or is this a dedicated VPN concentrator?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 05:50:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5286469#M1120809</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-04-30T05:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120 Remote Access VPN issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5286473#M1120810</link>
      <description>&lt;P&gt;RA VPN need mandetory ftd cert., do you have one?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 06:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5286473#M1120810</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-30T06:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120 Remote Access VPN issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5287055#M1120837</link>
      <description>&lt;P&gt;Is there a device in front of the FTD that could block ICMP or SSL/IPSec?&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Just Comcast modem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you ping from the FTD CLI to the internet?&lt;/P&gt;&lt;P&gt;-&amp;nbsp;Yes I can ping the ISP connection from the FTD CLI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is routing setup correctly via the outside interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;-&amp;nbsp;I've setup default route pointing to ISP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you access the internet through the FTD or is this a dedicated VPN concentrator?&lt;/P&gt;&lt;P&gt;&amp;nbsp;- I can access internet through FTD. The FTD is acting as the gateway for the internal network and also Remote access VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;V/R,&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2025 00:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5287055#M1120837</guid>
      <dc:creator>d-satbir</dc:creator>
      <dc:date>2025-05-02T00:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120 Remote Access VPN issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5287056#M1120838</link>
      <description>&lt;P&gt;Yes I've setup self signed cert.&amp;nbsp;&lt;/P&gt;&lt;P&gt;V/R,&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2025 00:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5287056#M1120838</guid>
      <dc:creator>d-satbir</dc:creator>
      <dc:date>2025-05-02T00:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120 Remote Access VPN issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5295975#M1121218</link>
      <description>&lt;P&gt;I still haven't been able to figure out this issue and was hoping that someone out there has come across this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would appreciate ton if anyone could help and give me some clues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 23:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5295975#M1121218</guid>
      <dc:creator>d-satbir</dc:creator>
      <dc:date>2025-06-02T23:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120 Remote Access VPN issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5296091#M1121221</link>
      <description>&lt;P&gt;Could you please share initially the sanitized output of the following commands from the FTD CLI?&lt;/P&gt;
&lt;P&gt;show asp table socket&lt;BR /&gt;show run webvpn&lt;/P&gt;
&lt;P&gt;Also, do you happen to have any inbound rules on this firewall? the issue could also be related to a one-to-one NAT rule that translates all the traffic hitting the FTD outside interface to something in the inside network.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 09:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5296091#M1121221</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-06-03T09:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120 Remote Access VPN issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5338084#M1123154</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The output of the commands you listed above:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Protocol Socket State Local Address Foreign Address&lt;BR /&gt;SSL 000052f8 LISTEN XXX.XXX.XXX.XXX:443 0.0.0.0:*&lt;BR /&gt;DTLS 008037f8 LISTEN XXX.XXX.XXX.XXX:443 0.0.0.0:*&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;gt; show running-config webvpn&lt;BR /&gt;webvpn&lt;BR /&gt;enable outside&lt;BR /&gt;http-headers&lt;BR /&gt;hsts-server&lt;BR /&gt;enable&lt;BR /&gt;max-age 31536000&lt;BR /&gt;include-sub-domains&lt;BR /&gt;no preload&lt;BR /&gt;hsts-client&lt;BR /&gt;enable&lt;BR /&gt;x-content-type-options&lt;BR /&gt;x-xss-protection&lt;BR /&gt;content-security-policy&lt;BR /&gt;anyconnect image disk0:/anyconnpkgs/cisco-secure-client-win-5.1.7.80-webdeploy-k9.pkg 2&lt;BR /&gt;anyconnect image disk0:/anyconnpkgs/cisco-secure-client-macos-5.1.7.80-webdeploy-k9.pkg 3&lt;BR /&gt;anyconnect profiles &amp;lt;name&amp;gt; disk0:/anyconncprofs/&amp;lt;profile&amp;gt;.xml&lt;BR /&gt;anyconnect enable&lt;BR /&gt;tunnel-group-list enable&lt;BR /&gt;cache&lt;BR /&gt;disable&lt;BR /&gt;error-recovery disable&lt;BR /&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't have the inbound rules on the firewall and neither the one to one NAT rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone assist with how the ACL rule and NAT rule should be configured?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 16:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5338084#M1123154</guid>
      <dc:creator>d-satbir</dc:creator>
      <dc:date>2025-10-13T16:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120 Remote Access VPN issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5344089#M1123361</link>
      <description>&lt;P&gt;So far I can't see any issue from the output you shared. The firewall seems to be listening on port 443/udp and 443/tcp. My recommendation for the next step would be to try to run some packet capture while you're trying to connect with the VPN.&lt;/P&gt;
&lt;P&gt;capture PACKCAP interface outside match tcp any host &amp;lt; the outside interface public IP &amp;gt; eq 443&lt;/P&gt;
&lt;P&gt;capture PACKCAP interface outside match udp any host &amp;lt; the outside interface public IP &amp;gt; eq 443&lt;/P&gt;
&lt;P&gt;show cap PACKCAP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you finish remove the capture with the command:&lt;/P&gt;
&lt;P&gt;no cap PACKCAP&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 14:07:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120-remote-access-vpn-issue/m-p/5344089#M1123361</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-11-03T14:07:19Z</dc:date>
    </item>
  </channel>
</rss>

