<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower Networking issue between interface port in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/firepower-networking-issue-between-interface-port/m-p/4505210#M235704</link>
    <description>&lt;P&gt;Each port runs different VLANs in the switch where they are connected, you should not see this issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how is your switch configured?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to access from Guest user to Inside, check the Logs in firepower is this reaching firepower or switch doing any routing here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Nov 2021 19:56:05 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-11-18T19:56:05Z</dc:date>
    <item>
      <title>Firepower Networking issue between interface port</title>
      <link>https://community.cisco.com/t5/wireless/firepower-networking-issue-between-interface-port/m-p/4505204#M235703</link>
      <description>&lt;P&gt;Hello Engineers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I found there is critical security issue on our Firepower. (2110 series)&lt;/P&gt;&lt;P&gt;On our Firepower, there are 3 interface ports, Outside/Inside/Guest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Those IP ranges has different, and Inside/Guest has private IP ranges.&lt;/P&gt;&lt;P&gt;Guest interface is for wireless Guest users.&lt;/P&gt;&lt;P&gt;Normally Guest users are not able to access Inside IP blocks, can't communicate with each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My case, Guest IP range can communicate with Inside!!!!!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Firepower --- Core switch --- Wireless Controller&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-There is no route for guest interface and Guest zone in Firepower.&lt;/P&gt;&lt;P&gt;-There is no route for Guest IP range in Core switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know where should I check... Please help, it is urgent to me..&lt;/P&gt;&lt;P&gt;How can different interface port can communicate without routing??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really appreciate your comments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 19:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/firepower-networking-issue-between-interface-port/m-p/4505204#M235703</guid>
      <dc:creator>eeebbunee</dc:creator>
      <dc:date>2021-11-18T19:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Networking issue between interface port</title>
      <link>https://community.cisco.com/t5/wireless/firepower-networking-issue-between-interface-port/m-p/4505210#M235704</link>
      <description>&lt;P&gt;Each port runs different VLANs in the switch where they are connected, you should not see this issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how is your switch configured?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to access from Guest user to Inside, check the Logs in firepower is this reaching firepower or switch doing any routing here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 19:56:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/firepower-networking-issue-between-interface-port/m-p/4505210#M235704</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-18T19:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Networking issue between interface port</title>
      <link>https://community.cisco.com/t5/wireless/firepower-networking-issue-between-interface-port/m-p/4505626#M235732</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;Can you share screen from your Firepower 2110? How it is managed - via FMC or FDM?&lt;/P&gt;&lt;P&gt;Are you sure, that cause of this problem inside Firepower? Maybe you need to implement ACL inside your core-switch or any L3 device.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 14:59:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/firepower-networking-issue-between-interface-port/m-p/4505626#M235732</guid>
      <dc:creator>kapydan88</dc:creator>
      <dc:date>2021-11-19T14:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Networking issue between interface port</title>
      <link>https://community.cisco.com/t5/wireless/firepower-networking-issue-between-interface-port/m-p/4505795#M235736</link>
      <description>&lt;P&gt;Hello Balaji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, Guest and inside port from FTD are connected to Core switch with different vlan.&lt;/P&gt;&lt;P&gt;WLC1/1-1/4 ports (Trunk)==== Core switch po1 LAG&lt;/P&gt;&lt;P&gt;&amp;nbsp;* WLC guest-interface VLAN300, ip address 192.168.0.2 / 255.255.255.0 / 192.168.0.1&lt;/P&gt;&lt;P&gt;Core switch inside ==== FTD Ethernet1/2&amp;nbsp;&lt;/P&gt;&lt;P&gt;Core switch Guest(VLAN300, no int vlan 300 ip address) ==== FTD Ethernet 1/3 (192.168.0.1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FTD DHCP Server enabled for Guest Network (192.168.0.3-192.168.0.200)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I connect Guest wireless, I get IP from FTD and connect internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have other site office, same configurations (almost similar) (FTD,Core switch, WLC). There, without no access-list (deny) rule in Core switch, guest network is not able to communicate with inside networks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you think that's because of Core switch or WLC? (not FTD)?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 17:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/firepower-networking-issue-between-interface-port/m-p/4505795#M235736</guid>
      <dc:creator>eeebbunee</dc:creator>
      <dc:date>2021-11-22T17:23:41Z</dc:date>
    </item>
  </channel>
</rss>

