<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC-FTD NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318837#M1122155</link>
    <description>&lt;P&gt;Change on remote FTD? There is no my script on the link. Or on FTD which is under FMC?&lt;/P&gt;</description>
    <pubDate>Fri, 08 Aug 2025 11:40:40 GMT</pubDate>
    <dc:creator>Denis Negik</dc:creator>
    <dc:date>2025-08-08T11:40:40Z</dc:date>
    <item>
      <title>FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318815#M1122153</link>
      <description>&lt;P&gt;Good day. Remote FTD has a public IP. FMC is in another office and has an internal IP. I am trying to make a NAT translation of TCP port 8305 on FTD behind which FCM is located.&lt;/P&gt;&lt;P&gt;I created auto nat rule – static. InterfaceObjects: Source-any, Destination-outside. Translation: OriginalSource-local IP FMC, Port TCP 8305. Translated Packet: Destination Interface IP, Port 8305.&lt;/P&gt;&lt;P&gt;In ACL:&lt;/P&gt;&lt;P&gt;Source-Zone Inside, Network - public IP of remote FTD, port 8305.&lt;/P&gt;&lt;P&gt;Destination-Zone Outside, Network local ip FMC, port 8305&lt;/P&gt;&lt;P&gt;I cannot connect FTD with this configuration. Tell me where the error is.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 10:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318815#M1122153</guid>
      <dc:creator>Denis Negik</dc:creator>
      <dc:date>2025-08-08T10:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318819#M1122154</link>
      <description>&lt;P&gt;check below&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 12:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318819#M1122154</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-08T12:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318837#M1122155</link>
      <description>&lt;P&gt;Change on remote FTD? There is no my script on the link. Or on FTD which is under FMC?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 11:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318837#M1122155</guid>
      <dc:creator>Denis Negik</dc:creator>
      <dc:date>2025-08-08T11:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318841#M1122156</link>
      <description>&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;check below&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 12:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318841#M1122156</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-08T12:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318846#M1122157</link>
      <description>&lt;P&gt;I drew it as is&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 11:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318846#M1122157</guid>
      <dc:creator>Denis Negik</dc:creator>
      <dc:date>2025-08-08T11:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318848#M1122158</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1866465"&gt;@Denis Negik&lt;/a&gt;&amp;nbsp;the ACL you refer to is on the FTD in front of the FMC? The rule is for traffic from the remote FTD to the FMC which is on the inside of the FTD. In which case, surely the Source Zone should be OUTSIDE and destination should be INSIDE?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you still have a problem run&amp;nbsp;&lt;STRONG&gt;system support firewall-engine-debug&amp;nbsp;&lt;/STRONG&gt;apply a filter and generate traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 11:43:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318848#M1122158</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-08T11:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318853#M1122159</link>
      <description>&lt;P&gt;You want to config FTD in which FMC is behind ? not remote FTD ?&lt;BR /&gt;if FTD in which FMC behind&amp;nbsp;&lt;BR /&gt;1- you need &lt;STRONG&gt;prefilter&lt;/STRONG&gt; config of ACL allow traffic between remote FTD and FMC bypass Snort inspect&lt;/P&gt;
&lt;P&gt;2- and need to swapping zone, the traffic is initiate from outside&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 12:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318853#M1122159</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-08T12:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318877#M1122160</link>
      <description>&lt;P&gt;&lt;STRONG&gt;system support firewall-engine-debug&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;after specifying all the data, nothing shows. Or does it not work via ssh? of course the problem remains&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 12:21:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318877#M1122160</guid>
      <dc:creator>Denis Negik</dc:creator>
      <dc:date>2025-08-08T12:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318878#M1122161</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1866465"&gt;@Denis Negik&lt;/a&gt;&amp;nbsp;are the zones correct though? Provide screenshot if you wish us to confirm.&lt;/P&gt;
&lt;P&gt;You SSH to the FTD you've applied the firewall rule to (the FTD in front of the FMC), just filter on the source IP address and generate some traffic to generate some output.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 12:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318878#M1122161</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-08T12:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318888#M1122162</link>
      <description>&lt;P&gt;that's how it's set up&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 12:47:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318888#M1122162</guid>
      <dc:creator>Denis Negik</dc:creator>
      <dc:date>2025-08-08T12:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318891#M1122163</link>
      <description>&lt;P&gt;FTD WAN remote IP ? that again confuse me&amp;nbsp;&lt;BR /&gt;let make it more simple&amp;nbsp;&lt;BR /&gt;FTD1-ISP-FTD2-FMC&amp;nbsp;&lt;BR /&gt;&amp;nbsp;in FMC2&amp;nbsp;&lt;BR /&gt;you need to config NAT using FMC real IP and FTD2 WAN IP&amp;nbsp;&lt;BR /&gt;confirm you do that ?&lt;BR /&gt;&lt;BR /&gt;if Yes then from FMC access to FTD2 and use capture to see if FTD1 send traffic or not&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (303).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/249963iC1E3B0029A37F50C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (303).png" alt="Screenshot (303).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 12:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318891#M1122163</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-08T12:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318898#M1122164</link>
      <description>&lt;P&gt;&lt;SPAN&gt;FTD WAN remote IP ? -&amp;nbsp;public IP address of the FTD1 port manager according to the scheme FTD1-ISP-FTD2-FMC&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 13:17:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318898#M1122164</guid>
      <dc:creator>Denis Negik</dc:creator>
      <dc:date>2025-08-08T13:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318903#M1122165</link>
      <description>&lt;P&gt;but FMC behind FTD2 and NAT config in FTD2 why you use FTD1 WAN IP in NAT config in FDT2?&lt;/P&gt;
&lt;P&gt;that wrong&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-FTD1 must config mgmt using FTD2 WAN IP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-FTD2 have ACL allow traffic between FTD1 and FMC&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-FTD2 have NAT between FMC private IP and FTD2 WAN public IP&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 14:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318903#M1122165</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-08T14:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318926#M1122166</link>
      <description>&lt;P&gt;I don't want to use wan port now. Is&amp;nbsp;it a necessary condition? I assigned&amp;nbsp;public ip for the manager port.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 14:18:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318926#M1122166</guid>
      <dc:creator>Denis Negik</dc:creator>
      <dc:date>2025-08-08T14:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318928#M1122167</link>
      <description>&lt;P&gt;Remember this for &lt;STRONG&gt;NAT&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;You want to use FTD2 public IP not FTD2 WAN port ?&lt;/P&gt;
&lt;P&gt;If that your Q' yes you can use public IP of FTD2.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 14:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318928#M1122167</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-08T14:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318933#M1122169</link>
      <description>&lt;P&gt;What does FTD2 have to do with this? It feels like you're not talking to me. )) From which of my answers do you take this?&amp;nbsp;You asked me about NAT. I made you screenshots and ACL. You didn't say anything about them at all. Is it configured correctly or not.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 14:45:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318933#M1122169</guid>
      <dc:creator>Denis Negik</dc:creator>
      <dc:date>2025-08-08T14:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: FMC-FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318942#M1122172</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (1003).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/249970i940A15DDD1EE417B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (1003).png" alt="Screenshot (1003).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;this clear NOW&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 14:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-nat/m-p/5318942#M1122172</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-08T14:49:50Z</dc:date>
    </item>
  </channel>
</rss>

