cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2542
Views
1
Helpful
1
Replies

IPSEC through a Cisco FTD

gamoore
Level 1
Level 1

I need to create a rule to allow IPsec/ISAKMP traffic trough a FTD 2100. The rule for the ISAKMP is pretty straight forward, allow udp 500 and/or 4500. But how do you define the rule to allow protocol esp?

1 Accepted Solution

Accepted Solutions

Rahul Govindan
VIP Alumni
VIP Alumni

You can create a rule under Access-Control Policy to allow ESP by choosing ESP(50) under the destination port. Picture attached:

 

esp-ftd.PNGThis translates to the following rule on the CLI

access-list CSM_FW_ACL_ line 22 advanced permit esp ifc inside any any rule-id 268440576

 

View solution in original post

1 Reply 1

Rahul Govindan
VIP Alumni
VIP Alumni

You can create a rule under Access-Control Policy to allow ESP by choosing ESP(50) under the destination port. Picture attached:

 

esp-ftd.PNGThis translates to the following rule on the CLI

access-list CSM_FW_ACL_ line 22 advanced permit esp ifc inside any any rule-id 268440576

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card