07-14-2021 08:48 AM
Hi Guys,
I noticed that all the HITS COUNTS of all OUTSIDE rules are empty. I enabled LOGGING but I can't even see the traffic coming from Outside to Inside
Outise > IPSEC Tunnel > Inside
Any ideas why
thanks
Solved! Go to Solution.
07-14-2021 11:46 AM
The issue was the Bypass Access Control policy for decrypted traffic (sysopt permit-vpn)
it's disabled by default on the Cisco FDM, but enabled by default on the Cisco FMC.
07-14-2021 08:54 AM
Has the VPN been established? Run the command "show crypto ipsec sa" from the CLI of the FTD and check the encaps and decaps counters are increasing.
If the counters are not increasing, do you have a NAT exemption rule, that ensures traffic destined over the VPN is not unintentially translated.
Please provide a screenshot of your Access Control policies, related to the VPN acces.
07-14-2021 09:49 AM
Hi Rob,
The VPN is established and working fine. The only issue is that I can't see any hits from Outside to Inside. I can't even see the VPN traffic from Outside to Inside
I have NAT from INSIDE to OUTSIDE on both ends
07-14-2021 11:46 AM
The issue was the Bypass Access Control policy for decrypted traffic (sysopt permit-vpn)
it's disabled by default on the Cisco FDM, but enabled by default on the Cisco FMC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide