10-09-2024 04:47 AM
We have a Firepower 2130 that has all it's NAT rules/policies as being imported from our old ASA 5525. The ASA is still in production for a different purpose. While I can see the NAT rules on the Firepower, I can't edit them unless it's done on the ASA. That being said I'm unable to determine if the ASA were to go down would the NAT rules go down with it or are the NAT rules on the FP still locked in until the ASA would be restored?
10-09-2024 06:57 AM
It's unclear from your question how the 2130 is not currently receiving traffic but...
If traffic switches over to flow via your Firepower 2130, it would work pretty much the same as your ASA - assuming you migrated the configuration correctly.
10-09-2024 07:09 AM
I'm confused as I don't think that answers my concern... All I'm concerned about is if the ASA were to go down if the NAT rules on the FP will go down with them & where to check or confirm this?
10-09-2024 07:12 AM
You run ASA on Firepower
So there is only one NAT' the NAT in lina of ASA
There is no NAT in firepower
MHM
10-09-2024 07:18 AM
We have both an ASA and a FP in our setup for separate purposes. Boh are physical devices. Only the NAT policies on the FP appear to be pulling from the ASA.
10-09-2024 07:24 AM
Sorry again' how it pulling?
You use some kind of migrate tool?
MHM
10-09-2024 07:42 AM
Not sure, this was configured years before our team came in.
10-09-2024 07:51 AM
There is no such thing as a device running FTD actively "pulling" rules (NAT or otherwise) from an ASA.
ASA configuration can be migrated to FTD but that is a one time action using the separate migration tool.
10-09-2024 08:13 AM
Odd then, as this is what I'm running into.
On FMC
Devices > NAT > [Selected NAT Policy] > Can see the NAT rules, but unable to edit or modify them.
When I click on the pencil icon to edit the rule the option to enable/disable the rule is grey'd out. There is also a banner which states "Policy created from ASA with hostname *ASA*"
When I login to the ASA I can view & then subsequently edit the same rules.
10-09-2024 10:02 AM
If the NAT policy edit icon is greyed out, it would most likely be a user privilege level issue. The banner you mention is just a description field which one can optionally enter for a NAT or Access Control policy to provide additional information about it.
Are you logging in an admin user or username with admin level privilege?
10-09-2024 11:56 AM
Admin User & I can edit some of the rules, that I know I created locally on the FTD, just not any of the previously existing NAT rules that also on the ASA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide