<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Firepower running in VMWare Workstation - FTD not intercepting traffic. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-firepower-running-in-vmware-workstation-ftd-not/m-p/3698007#M132782</link>
    <description>&lt;P&gt;For Vmware workstation yo need to edit a config file to enable promiscuous mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://superuser.com/questions/1209497/how-do-you-enable-promiscuous-mode-in-vmware-workstation" target="_blank"&gt;https://superuser.com/questions/1209497/how-do-you-enable-promiscuous-mode-in-vmware-workstation&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However FTDv is NOT supported on VMWare workstation. Here's the support matrix:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html#id_37873" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html#id_37873&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Aug 2018 15:20:47 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-08-30T15:20:47Z</dc:date>
    <item>
      <title>Cisco Firepower running in VMWare Workstation - FTD not intercepting traffic.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-running-in-vmware-workstation-ftd-not/m-p/3697802#M132768</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am currently setting up Firepower FTD in VMWare Workstation, and was hoping someone could possibly help me with an issue I am experiencing with the FTD not intercepting and blocking/allowing traffic?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A bit background:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I now have a paired FMC and FTD running on VMWare Workstation. The FTD has three virtual NICs, set up as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nic1 (Management) - Using VMNET2, which is configured in NAT mode within VMWare. FMC is configured to also use VMNET2 nic.&lt;/P&gt;
&lt;P&gt;Nic2 (Outer) - Using the bridged option in VMware for this NIC. Has an IP address in the same range as office router.&lt;/P&gt;
&lt;P&gt;Nic3 (Inner) - Using the bridged option in VMWare for this NIC. Has a 172.xx.xx.2 internal address. Virtual client desktop that I also built also uses the bridged NIC option with an IP address in the same network space, and is set with gateway of 172.xx.xx.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, the problem that i am facing is that my virtual client PC can ping the inner interface of the FTD, but when I attempt to do a ping from the client desktop to the internet, it times out. I have created a blanket ACL on the FTD to allow all traffic outbound, from all networks, but it is still not working. What is strange, is that when i attempt the ping, nothing appears in the event/connection logs on the FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can confirm that the FTD can ping externally and has internet connectivity, so both outer and inner up and running, at least from an IP perspective at least.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To confirm, I am running VMWare Workstation 14.1.3 on Fedora 28, with firewalld disabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have heard this might be something to do with promiscuous mode needing enabled? I am a total linux newbie, so really struggling and not sure how to do this, and/or whether my overall config is essesntially correct/incorrect. Can you please help or advise?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Craig.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:10:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-running-in-vmware-workstation-ftd-not/m-p/3697802#M132768</guid>
      <dc:creator>crstephenson</dc:creator>
      <dc:date>2020-02-21T16:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower running in VMWare Workstation - FTD not intercepting traffic.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-running-in-vmware-workstation-ftd-not/m-p/3697857#M132773</link>
      <description>&lt;P&gt;Yes your dataplane network adapters for the FTDv host need to have promiscuous mode enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You do that this for the associated vSwitch as shown below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ESXi vSwitch promiscuous mode.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/17820iD0477F6FCEB50BCB/image-size/large?v=v2&amp;amp;px=999" role="button" title="ESXi vSwitch promiscuous mode.PNG" alt="ESXi vSwitch promiscuous mode.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It's not a Linux thing per se - it's an ESXi setting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.vmware.com/s/article/1004099?CoveoV2.CoveoLightningApex.getInitializationData=1&amp;amp;ui-force-components-controllers-hostConfig.HostConfig.getConfigData=1&amp;amp;r=2&amp;amp;other.KM_Utility.getArticleDetails=1&amp;amp;other.KM_Utility.getArticleMetadata=1&amp;amp;other.KM_Utility.getUrl=1&amp;amp;other.KM_Utility.getUser=1&amp;amp;other.KM_Utility.getAllTranslatedLanguages=1&amp;amp;ui-comm-runtime-components-aura-components-siteforce-qb.Quarterback.validateRoute=1" target="_blank"&gt;https://kb.vmware.com/s/article/1004099?CoveoV2.CoveoLightningApex.getInitializationData=1&amp;amp;ui-force-components-controllers-hostConfig.HostConfig.getConfigData=1&amp;amp;r=2&amp;amp;other.KM_Utility.getArticleDetails=1&amp;amp;other.KM_Utility.getArticleMetadata=1&amp;amp;other.KM_Utility.getUrl=1&amp;amp;other.KM_Utility.getUser=1&amp;amp;other.KM_Utility.getAllTranslatedLanguages=1&amp;amp;ui-comm-runtime-components-aura-components-siteforce-qb.Quarterback.validateRoute=1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 12:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-running-in-vmware-workstation-ftd-not/m-p/3697857#M132773</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-08-30T12:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower running in VMWare Workstation - FTD not intercepting traffic.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-running-in-vmware-workstation-ftd-not/m-p/3697893#M132776</link>
      <description>&lt;P&gt;Thanks, Marvin.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I'm not using ESXi. I'm using VMWare Workstation.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 13:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-running-in-vmware-workstation-ftd-not/m-p/3697893#M132776</guid>
      <dc:creator>crstephenson</dc:creator>
      <dc:date>2018-08-30T13:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower running in VMWare Workstation - FTD not intercepting traffic.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-running-in-vmware-workstation-ftd-not/m-p/3698007#M132782</link>
      <description>&lt;P&gt;For Vmware workstation yo need to edit a config file to enable promiscuous mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://superuser.com/questions/1209497/how-do-you-enable-promiscuous-mode-in-vmware-workstation" target="_blank"&gt;https://superuser.com/questions/1209497/how-do-you-enable-promiscuous-mode-in-vmware-workstation&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However FTDv is NOT supported on VMWare workstation. Here's the support matrix:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html#id_37873" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html#id_37873&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 15:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-running-in-vmware-workstation-ftd-not/m-p/3698007#M132782</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-08-30T15:20:47Z</dc:date>
    </item>
  </channel>
</rss>

