Access-list in FMC and ASA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2021 01:42 PM
Hello guys,
We have ASA-5555-X with sourcepower which is mnaged by FMC. If we create ACL in fmc and deploy, won't it be shown in ASA Cli? But, we can not see there. Also have applied the 'sfr_direct permit ip any any' statement to redirect traffic. Is there anything to do that i'm missing?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2021 03:21 PM
Hi,
It seems you are using ASA 5555-X appliance with ASA software + firepower module. Are you checking the firepower config from firepower console or asa cli ?
Firepower config you made will not visible in ASA cli, you may see config under firepower module cli by login it from asa cli with below command:
asa# session sfr console
Just a quick note, in your scenario, your ASA firewall policies will be different than your firepower policies created by sourcefire.
Depends on your ASA policies, traffic will be sent to Firepower module after hitting ASA rules which allows inspection through Firepower module. Once sent then your FMC policies will be applied to traffic
Firep
