<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD block traffic in same VLAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375069#M923990</link>
    <description>&lt;P&gt;Can you share cli packet-tracer output?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alos it looks like you are using custom MAC addresses all beginning with 0000.0000.000x. I wonder if this is causing any problem?&lt;/P&gt;</description>
    <pubDate>Sun, 29 Apr 2018 14:18:47 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-04-29T14:18:47Z</dc:date>
    <item>
      <title>FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3373664#M923987</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have Ftd &amp;nbsp;but still in test environment as &amp;nbsp;we have try to get it on production two times but it fail because it blocks the traffic in the &amp;nbsp;same vlan i know its wired but that what happened the hosted&amp;nbsp;in same vlan is blocked a cant even ping its always say ping translate&amp;nbsp;fail . I have upgraded to 6.2.3 &amp;nbsp;and the same issues&amp;nbsp;exist ..&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;any help to solve it&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:40:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3373664#M923987</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2020-02-21T15:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3373723#M923988</link>
      <description>&lt;P&gt;Unlike with classic ASA software, Firepower Threat Defense by default allows same-security traffic both inter- and intra-interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share screenshots of your access control policy and interface settings? you might also use packet-tracer to check what's happening with a test traffic flow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200908-configuring-firepower-threat-defense-int.html#anc16" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200908-configuring-firepower-threat-defense-int.html#anc16&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, architecturally, why would traffic within a VLAN even attempt to transit the FTD appliance? Normally a host would arp for the destination address and, finding it, send the traffic directly to the destination MAC address and not use any gateway or network-based firewall or IPS.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 13:24:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3373723#M923988</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-04-26T13:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375067#M923989</link>
      <description>&lt;P&gt;i know its&amp;nbsp; wired that its block traffic in L2 but that what&amp;nbsp;really&amp;nbsp;&amp;nbsp;happen .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there is the screen shot and the packet tracer output y will see it drooped&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and i have capture the L2 traffic y will see what happen&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="access rule  policy .JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/11233i686B857301A5B8EA/image-size/large?v=v2&amp;amp;px=999" role="button" title="access rule  policy .JPG" alt="access rule  policy .JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captccure.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/11234i538A066860FD0F33/image-size/large?v=v2&amp;amp;px=999" role="button" title="Captccure.JPG" alt="Captccure.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/11235i778A9BF7DC3E9A41/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture2.JPG" alt="Capture2.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD JPG.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/11236i8EFA891EF6C845DA/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTD JPG.JPG" alt="FTD JPG.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/11237iBA5EEF747ED3831E/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTD.JPG" alt="FTD.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Apr 2018 14:06:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375067#M923989</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-04-29T14:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375069#M923990</link>
      <description>&lt;P&gt;Can you share cli packet-tracer output?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alos it looks like you are using custom MAC addresses all beginning with 0000.0000.000x. I wonder if this is causing any problem?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Apr 2018 14:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375069#M923990</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-04-29T14:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375079#M923991</link>
      <description>&lt;P&gt;&amp;gt; packet-tracer input Core-Vlan tcp 192.168.0.200 111 192.168.0.201 11&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 192.168.0.201 using egress ifc Core-Vlan&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;access-group CSM_FW_ACL_ global&lt;BR /&gt;access-list CSM_FW_ACL_ advanced deny ip any any rule-id 268434432 event-log flow-start &lt;BR /&gt;access-list CSM_FW_ACL_ remark rule-id 268434432: ACCESS POLICY: default - Default&lt;BR /&gt;access-list CSM_FW_ACL_ remark rule-id 268434432: L4 RULE: DEFAULT ACTION RULE&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: Core-Vlan&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: Core-Vlan&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;</description>
      <pubDate>Sun, 29 Apr 2018 14:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375079#M923991</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-04-29T14:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375081#M923992</link>
      <description>&lt;P&gt;how&amp;nbsp; &lt;SPAN&gt;&amp;nbsp;custom MAC addresses&amp;nbsp;&lt;/SPAN&gt;make problem&amp;nbsp; ?&lt;/P&gt;
&lt;P&gt;its not duplicate&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Apr 2018 14:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375081#M923992</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-04-29T14:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375085#M923993</link>
      <description>&lt;P&gt;The custom MAC addresses aren't necessarily a problem. But a basic rule is when there is a problem, we look for unusual settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your packet-tracer shows the traffic being denied due to an ACL. Have a look at your access control and prefilter policies.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Apr 2018 15:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375085#M923993</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-04-29T15:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375281#M923994</link>
      <description>&lt;P&gt;the question&amp;nbsp; now why FTD act in L2 instead of Switchs&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 09:15:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3375281#M923994</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-04-30T09:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3378880#M923995</link>
      <description>&lt;P&gt;did you have see&amp;nbsp;this&amp;nbsp; TCP wireshark ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 May 2018 13:16:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3378880#M923995</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-05-06T13:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3380757#M923996</link>
      <description>&lt;P&gt;Your FTD device can also be setup to do integrated routing and bridging, thus effectively acting as a switch. If so, you need a policy to permit inter-interface traffic within a given BVI group.&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 15:02:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3380757#M923996</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-09T15:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3383336#M923997</link>
      <description>how to check if my FTD do integrated routing and bridging &lt;BR /&gt;and how can i disable it .&lt;BR /&gt;</description>
      <pubDate>Tue, 15 May 2018 10:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3383336#M923997</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-05-15T10:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3383360#M923998</link>
      <description>&lt;P&gt;Have a look at the interfaces setup in FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there is integrated routing and bridging, there will be bridge groups and switched interfaces configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 10:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3383360#M923998</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-15T10:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3383806#M923999</link>
      <description>i have config sub interface under ether1/1 with many vlan so i think that i have Integrated Routing and Bridging  but i have read alot it its control the traffic bet different vlan not in same vlan &lt;BR /&gt;but i ll try to remove it i use the interfaces and see if still block traffic or not &lt;BR /&gt;i ll check and feed you back .</description>
      <pubDate>Tue, 15 May 2018 20:55:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3383806#M923999</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-05-15T20:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3386020#M924000</link>
      <description>&lt;P&gt;could you tell me why&amp;nbsp;FTD&amp;nbsp;&amp;nbsp;act like this&amp;nbsp; .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 07:59:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3386020#M924000</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-05-20T07:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3386071#M924001</link>
      <description>&lt;P&gt;Well you seem to have two Cisco devices configured with the IP address 192.168.0.9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;00:24:51 Cisco Systems, Inc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;38:90:A5 Cisco Systems, Inc&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You've not shared sufficient details of your setup to let us provide any further insight. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If this is under support you might just open a TAC case and the engineer can work with you in real time. If it's just a lab then why not share the full configuration?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 13:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3386071#M924001</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-20T13:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3386292#M924002</link>
      <description>&lt;P&gt;&lt;SPAN&gt;00:24:51 Cisco Systems, Inc &amp;gt;&amp;gt;&amp;gt;&amp;gt; is a layer two Switch has Vlan interface with IP 192.168.0.9&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;38:90:A5 Cisco Systems, Inc&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;nbsp; the FTD&amp;nbsp; and its have a sub interface with 192.168.0.254&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;there is no duplicaion in IPs&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;but always the FTD do this issuse and that why the traffic is blocked in Layer 2 .&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;this scenario&amp;nbsp;&amp;nbsp;&amp;nbsp;was a going to be a production&amp;nbsp;but after a lot&amp;nbsp;of failure&amp;nbsp;&amp;nbsp;downtime its&amp;nbsp;become&amp;nbsp;a lab to test and insure that will&amp;nbsp;run in production&amp;nbsp;with no issues.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 08:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3386292#M924002</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-05-21T08:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3386353#M924003</link>
      <description>&lt;P&gt;I recommend opening a TAC case spo the engineer can work with you in real time.&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 11:47:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3386353#M924003</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-21T11:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: FTD block traffic in same VLAN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3726222#M924004</link>
      <description>&lt;P&gt;it was miss config in nat command that turn the Device as proxy arp&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 09:52:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-block-traffic-in-same-vlan/m-p/3726222#M924004</guid>
      <dc:creator>khld.saad</dc:creator>
      <dc:date>2018-10-16T09:52:46Z</dc:date>
    </item>
  </channel>
</rss>

