11-05-2025 05:13 AM
Hello,
New to Firepower configuration. My inside wired network is working fine. It is vlan 1 and pretty much default configuration. I'm trying to add a new subnet to the inside for a wireless network. I connect my firepower to a router on another interface that is routed and not switched vlan, and from the subnet on the router I can ping the next hop address of the firewall but cannot ping out to the internet. I'm using 8.8.8.8 to ping out to. The trace stops at the firewall. I put new subnet in the same zone as the inside subnet that is working so that it will have the same policies as the one subnet that is working. Not sure what to check now. Thanks for any help.
Ken
11-05-2025 05:19 AM
gDay @kenhagen sounds like the routing and NAT might be the issue. Make sure ur new subnet is included in the NAT rule that translates inside traffic to the outside interface, and that there’s a route back to that subnet on the firewall. If VLAN 1 works and the new one doesn’t, it’s usually missing from NAT or policy...
ping me if it doesnt work......
hope it helps!
-Enes
11-05-2025 05:22 AM
Thanks I'll check on the NAT. I did put in a route back. Will get back to you. Thanks again.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide