cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
93
Views
0
Helpful
2
Replies

Firepower 1010 Configuration

kenhagen
Level 1
Level 1

Hello,

New to Firepower configuration.  My inside wired network is working fine.  It is vlan 1 and pretty much default configuration.  I'm trying to add a new subnet to the inside for a wireless network. I connect my firepower to a router on another interface that is routed and not switched vlan, and from the subnet on the router I can ping the next hop address of the firewall but cannot ping out to the internet.  I'm using 8.8.8.8 to ping out to.  The trace stops at the firewall. I put new subnet in the same zone as the inside subnet that is working so that it will have the same policies as the one subnet that is working.  Not sure what to check now.  Thanks for any help.

Ken

 

2 Replies 2

Enes Simnica
Spotlight
Spotlight

gDay @kenhagen sounds like the routing and NAT might be the issue. Make sure ur new subnet is included in the NAT rule that translates inside traffic to the outside interface, and that there’s a route back to that subnet on the firewall. If VLAN 1 works and the new one doesn’t, it’s usually missing from NAT or policy... 

ping me if it doesnt work......

hope it helps!

 

-Enes

more Cisco?!
more Gym?!



If this post solved your problem, kindly mark it as Accepted Solution. Much appreciated!

Thanks I'll check on the NAT.  I did put in a route back.  Will get back to you.  Thanks again.