cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2540
Views
0
Helpful
3
Replies

Dropped Packets on Cisco FTD

a.aljiledi
Level 1
Level 1

Hello.

 

I have two Firepower works on routing mode as showed on the diagram and client domain try access to the domain controller , the firepower 1 drop the DNS packet that returned by the domain controller after passed on the other firepower. 

 

based on the diagram i have a domain client PC trying access to the DNS server (Domain Controller) with UDP source random number and destination UDP 53.

 

the packet was successfully received by the end device (Domain Controller) but when the domain controller replay to the client the firepower 1 drop the packet with ( source UDP port 53 and the destination port is random).

 

any idea to resolve this ?? 

3 Replies 3

At the very least you should also include the log message that you are seeing on Firepower1 when indicating that it is being dropped there. 

- is there any NAT configured on Firepower1 or Firepower2?

 

--
Please remember to select a correct answer and rate helpful posts

Thank you for replay..

 

the log say the destination port random UDP not allowed,,, There is no NATING

 

I think this issue because the both Firepower working on routing mode and in this case the Firepower 1 when receive the packet from the Firepower 2 will drop it because it looks like a new session connection open not the same connection that opened by the domain client.

 

 

Could you please post a screenshot of the actual log message.  If it say "no existing connection", then this is an asynchronous routing issue.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card