ā03-14-2024 03:05 AM
Hello,
in company we have Cisco Firepower 1140 to this we have connected Cisco ISR and switch. We created new subnet for customer SDWAN to get access to internet from our ISP. So everything localy works. From ISR I can ping local IP address of our FTD with source of this new subnet but to outside like 8.8.8.8 I have issue. Basically there is no ping from this subnet to network even if we have other our subnets configured in same way and they are working fine. I added ACL rule to allow/trust traffic from this subnet to outside to all IPs and ports. Still same issue
Our FTDs are managed by FMC. In there in Packet Tracer we have error/deny by Snort (I attached screenshot from this part)
To be honest I am trying to solve it like a week now and I really need urgent help. I will be very grateful for any tips and solutions
ā03-14-2024 03:48 AM
Show access-list
The packet-tracer show rule ID that drop packet
Check this rule ID
MHM
ā03-14-2024 04:36 AM
Yes, I see this:
ā03-14-2024 04:42 AM
You mention that you add ACL, can I see the ACL in FTD
MHM
ā03-14-2024 04:47 AM
ā03-14-2024 05:25 AM
For ACL order I will make double check
But also what I notice is zone
The drop packey pass from zone2 to zone2 ? Can you also make double check this point.
MHM
ā03-14-2024 05:35 AM
Sorry, where you notice zone2? I checked screenshots and I cannot find them. We have zone "inside" and "outside" as our main zones in network
ā03-14-2024 06:37 AM
aa ok, found it in Packet Tracer. To be honest I am not sure why even if we don't have zone called "zone2"
ā03-14-2024 07:22 AM - edited ā03-14-2024 07:43 AM
can you share the lookup phase of packet-tracer
MHM
ā03-14-2024 07:37 AM
ā03-14-2024 07:53 AM
ā03-15-2024 01:35 AM
ohh ok got it but I don't know why it is to same zone (internet) even if it is configured correctly on ISR. Maybe you know what to check why it is happened?
ā03-16-2024 02:47 AM
can I see how you config the packet-tracer
thanks
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide