07-14-2021 08:48 AM
Hi Guys,
I noticed that all the HITS COUNTS of all OUTSIDE rules are empty. I enabled LOGGING but I can't even see the traffic coming from Outside to Inside
Outise > IPSEC Tunnel > Inside
Any ideas why
thanks
Solved! Go to Solution.
07-14-2021 11:46 AM
The issue was the Bypass Access Control policy for decrypted traffic (sysopt permit-vpn)
it's disabled by default on the Cisco FDM, but enabled by default on the Cisco FMC.
07-14-2021 08:54 AM
Has the VPN been established? Run the command "show crypto ipsec sa" from the CLI of the FTD and check the encaps and decaps counters are increasing.
If the counters are not increasing, do you have a NAT exemption rule, that ensures traffic destined over the VPN is not unintentially translated.
Please provide a screenshot of your Access Control policies, related to the VPN acces.
07-14-2021 09:49 AM
Hi Rob,
The VPN is established and working fine. The only issue is that I can't see any hits from Outside to Inside. I can't even see the VPN traffic from Outside to Inside
I have NAT from INSIDE to OUTSIDE on both ends
07-14-2021 11:46 AM
The issue was the Bypass Access Control policy for decrypted traffic (sysopt permit-vpn)
it's disabled by default on the Cisco FDM, but enabled by default on the Cisco FMC.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: