<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR and NAT order of operation on FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3926666#M938415</link>
    <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;I saw this document earlier, but it doesn't show where the PBR component sits in the order. Also the document doesn't explain the traffic flow through these different components. Example how does pre-filter fastpathed to L3, L2 hops work? Is there a some document (couldn't find in cisco live ones either) about the traffic flow though the FTD?&lt;/P&gt;</description>
    <pubDate>Thu, 19 Sep 2019 03:37:42 GMT</pubDate>
    <dc:creator>Madura Malwatte</dc:creator>
    <dc:date>2019-09-19T03:37:42Z</dc:date>
    <item>
      <title>PBR and NAT order of operation on FTD</title>
      <link>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3922181#M938412</link>
      <description>&lt;P&gt;I understand PBR works on FTD via flexconfig, but I wanted to double check the order of operations for NAT.&lt;/P&gt;&lt;P&gt;I have two ISP links and want to send traffic from a particular internal subnet out ISP2 instead of ISP1. After PBR is done on the FTD, would it then apply the NAT rule for the ISP2 interface? Is the FTD firepower software following the same order of operation as described in this document -&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/6209-5.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/6209-5.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3922181#M938412</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2020-02-21T17:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and NAT order of operation on FTD</title>
      <link>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3922324#M938413</link>
      <description>&lt;P&gt;Dear ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you will do policy route traffic will forcefully go with configured ISP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i suggest please make dedicated nat rule for this subnet and put in starting order .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also You can run packet tracer to watch traffic order .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Harmesh Yadav&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 09:06:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3922324#M938413</guid>
      <dc:creator>harmesh88</dc:creator>
      <dc:date>2019-09-11T09:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and NAT order of operation on FTD</title>
      <link>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3923176#M938414</link>
      <description>&lt;P&gt;The NGFW (FTD) policy order of operations is described in detail here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/firepower/Self-Help/NGFW_Policy_Order_of_Operations.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/firepower/Self-Help/NGFW_Policy_Order_of_Operations.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Here's a good visual guide excerpted from it:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD OOO reference.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/44491i0DBA4ED0522BF57B/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTD OOO reference.PNG" alt="FTD OOO reference.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 11:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3923176#M938414</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-12T11:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and NAT order of operation on FTD</title>
      <link>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3926666#M938415</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;I saw this document earlier, but it doesn't show where the PBR component sits in the order. Also the document doesn't explain the traffic flow through these different components. Example how does pre-filter fastpathed to L3, L2 hops work? Is there a some document (couldn't find in cisco live ones either) about the traffic flow though the FTD?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 03:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3926666#M938415</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2019-09-19T03:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and NAT order of operation on FTD</title>
      <link>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3926695#M938416</link>
      <description>&lt;P&gt;I have an older (2015) techzone document from Cisco which explains it thus:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;For the first packet in a flow, PBR processing occurs on the ingress interface to which it is applied BEFORE applying&amp;nbsp;NAT or module inspection on traffic (between steps 4 and 5 in the figure below). When traffic arrives that matches the&amp;nbsp;configured the routemap,&amp;nbsp;the ASA will do a route lookup to determine the egress interface. With PBR you can manually&amp;nbsp;take various actions on the traffic such as set next hop, set a DSCP value, set egress interface, etc. Once the egress&amp;nbsp;interface is determined, any inspection or NAT and CX/SF policies are processed as per the normal process.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Furthermore, when you have PBR configured, it will show up in packet-tracer output so you can see explicitly where it sits in order of operations on your particular device's configuration. It would normally show up as Phase 3 (after having been found to be a new connection and not denied by input ACL). Input ACL in classic ASA is roughly equivalent to prefilter in FTD. So you can say the PBR is after prefilter but before DAQ sends the traffic to Snort (= shorthand for the whole chain from SI through IPS in the diagram)&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 05:27:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-and-nat-order-of-operation-on-ftd/m-p/3926695#M938416</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-19T05:27:45Z</dc:date>
    </item>
  </channel>
</rss>

