<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with troubleshooting Firepower FTD VPN not passing traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772756#M983285</link>
    <description>&lt;HR /&gt;
&lt;P&gt;Sure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FTD1:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 649px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27077i4F7E32F85A7A8CE4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 680px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27078i96AD9A03CFEE24B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 652px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27079iDCF52AE400807E53/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FTD2:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 656px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27080iD78BA4316E760DE1/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 879px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27081i3BA7D8AF50835EB4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 830px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27082iFA14BC05A0DF0CFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jan 2019 09:32:09 GMT</pubDate>
    <dc:creator>mhmservice</dc:creator>
    <dc:date>2019-01-04T09:32:09Z</dc:date>
    <item>
      <title>Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772299#M983262</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am currently building a proof of concept with the following topology. It is all built inside a single VMware ESXI host.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27020i9DCFC36BDC194BBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I intend to configure a full mesh VPN between all four FTD devices to route between the LAN subnets (10.1.0.0/24,10.2.0.0/24,10.3.0.0/24,10.4.0.0/24)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a basic "hide" NAT rule setup from inside to outside on each FTD and there is an "any-any" access control policy in place on all the firewalls to rule that out as an issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PC 10.2.0.111 can ping the outside interface of FTD1 so I know the connectivity through R1 is working. The FMC can also connect to FTD2,FTD3,FTD4 management interfaces over R1 as they have been configured using this connection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is I can't seem to ping the sites from each other, e.g. PC 10.2.0.111 is unable to ping 10.1.0.111. I have checked windows firewall is turned off on the VMs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the full mesh VPN config page from FMC:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27021i1FB281DF9A77BA62/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;I thought the problem was the NAT policy so I configured as follows to try to get connectivity to work on FTD1:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27025i13299190AC2D0269/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And on FTD2:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27026i3C3E3C9A95E677A5/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show crypto ikev2 sa on FTD1 shows the tunnel (all other FTDs show similar)&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 723px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27022i14090D2BFC51AD7A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I ran a trace and it says the traffic is allowed:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27027i2AA327955052CFA0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyopne have more tips on how to troubleshoot this as i'm really stuck&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All help appreciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772299#M983262</guid>
      <dc:creator>mhmservice</dc:creator>
      <dc:date>2020-02-21T16:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772303#M983266</link>
      <description>&lt;P&gt;Do you have access control policies to permit the traffic?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 15:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772303#M983266</guid>
      <dc:creator>matty-boy</dc:creator>
      <dc:date>2019-01-03T15:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772335#M983270</link>
      <description>&lt;P&gt;I have the following policy on all FTD devices in place in an attempt to troubleshoot this:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27031i39BB519B602CEDB3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 16:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772335#M983270</guid>
      <dc:creator>mhmservice</dc:creator>
      <dc:date>2019-01-03T16:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772336#M983273</link>
      <description>&lt;P&gt;run a packet tracer to verify it first.&lt;/P&gt;&lt;P&gt;least it will tell you where the packet the droping&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 16:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772336#M983273</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-03T16:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772367#M983277</link>
      <description>&lt;P&gt;I ran the following packet tracer and it says "DROP" for ipsec-tunnel-flow but im not sure what specifically that means&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27033i7A64114868F1A548/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 16:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772367#M983277</guid>
      <dc:creator>mhmservice</dc:creator>
      <dc:date>2019-01-03T16:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772381#M983282</link>
      <description>&lt;P&gt;i think you packet trace does not give accurate result in terms of vpn.&lt;/P&gt;&lt;P&gt;can you sent constant ping from Site1_Lan to Site2_Lan in mean time check if phase 1 and phase 2 come up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have access to CLI on FTD give command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show crypto ikev1 sa&lt;/P&gt;&lt;P&gt;show crypto ipsec sa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 17:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772381#M983282</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-03T17:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772756#M983285</link>
      <description>&lt;HR /&gt;
&lt;P&gt;Sure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FTD1:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 649px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27077i4F7E32F85A7A8CE4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 680px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27078i96AD9A03CFEE24B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 652px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27079iDCF52AE400807E53/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FTD2:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 656px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27080iD78BA4316E760DE1/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 879px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27081i3BA7D8AF50835EB4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 830px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27082iFA14BC05A0DF0CFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 09:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772756#M983285</guid>
      <dc:creator>mhmservice</dc:creator>
      <dc:date>2019-01-04T09:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772758#M983287</link>
      <description>&lt;P&gt;can you please double check if the routing is properly in place. i can see the encap and no decap. most probably it could be a routing issue.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 09:35:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772758#M983287</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-04T09:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772774#M983289</link>
      <description>&lt;P&gt;I think that it is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FTD1:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 665px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27088i13BB88756395650E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FTD2:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 665px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27089i8DA115BF1372C83A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 09:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772774#M983289</guid>
      <dc:creator>mhmservice</dc:creator>
      <dc:date>2019-01-04T09:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772808#M983290</link>
      <description>&lt;P&gt;Double check that FTD2 PC has FTD2 inside interface as its gateway. That's the routing that is suspect given your output that you shared.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 11:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3772808#M983290</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-01-04T11:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Help with troubleshooting Firepower FTD VPN not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3775148#M983291</link>
      <description>&lt;P&gt;Finally fixed it ... subnet mask on PC 10.2.0.111 was set to 255.0.0.0 not 255.255.255.0 ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Stupid mistake on my part, but a mystery solved!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the hints&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 15:04:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-troubleshooting-firepower-ftd-vpn-not-passing-traffic/m-p/3775148#M983291</guid>
      <dc:creator>mhmservice</dc:creator>
      <dc:date>2019-01-08T15:04:47Z</dc:date>
    </item>
  </channel>
</rss>

