cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1032
Views
0
Helpful
1
Replies

Expose port on FirePower FDM 1010

AndrzejBanczak
Level 1
Level 1

Hello Team,

 

After two weeks of digging, searching, trying, watching and reading I kindly ask for Your help.

I make first steps with FirePower 1010 FDM 

 

What I did after unboxing is:

- registering the license 

- Thread/Malware/URL License/Intrusion are disabled

- WAN ETH 1/1 in DHCP mode (10.0.1.14) DNS - Cisco Umbrella

- Firmware update to 6.6.1-91

- Interface 1/8 I have set to access mode, assign vlan 2 and enabled dhcp server of range 192.168.2.10-20

- the vlan is added to inside_zone (standard one)

 

- I have connected Raspberry PI with open SSH server on port 1234 to int 1/8; Raspberry got IP: 192.168.2.100

- I have enabled rsyslog server on raspberry

 

- I have connected PC to port 1/2 - got IP 192.168.1.10

- Raspberry and FPW 1010 got internet connection

 

I am attaching screen - hope the configuration is clear

 

Team, how to expose SSH port 1234 from Raspberry that PC 10.0.1.20 will be able to connect to it? 

I have created various Static NAT rules and Access rules.

I can connect from 192.168.1.10 but I cannot connect from 10.0.1.20

I can not see anything from 10.0.1.20 in syslog server

Firepower itself is pingable from 10.0.1.20

 

What am I missing? 

 

 

diagram.png

NAT.png

accessRules.png

 

 

 

1 Accepted Solution

Accepted Solutions
1 Reply 1

AndrzejBanczak
Level 1
Level 1

It was a NAT issue. 

I have found solution here:

https://integratingit.wordpress.com/2020/02/08/ftd-configuration-using-fdm/

Review Cisco Networking for a $25 gift card