cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
628
Views
0
Helpful
1
Replies

Firepower ACP Source/Destination IP with Cisco ASA

kelvin.rk
Level 1
Level 1

Hi All,

 

Would like to ask, when we run Firepower Services (ver 6.2) on Cisco ASA (ver 9.6.1) and we apply NAT on the Cisco ASA (Source/Destination NAT) and redirect the traffic to SFR, when we configure Access Control Policy Rule, on the Access Control Policy Rule source/destination IP, should we use the real source/destination IP or should use the ASA NATed IP?

 

Thank you

Kelvin  

1 Reply 1

GRANT3779
Spotlight
Spotlight

Hi Kelvin,

 

To get some insight into the Order Of Operations and packet processing when FirePOWER is involved, see the attached link -

http://www.ciscopress.com/articles/article.asp?p=2730336&seqNum=7

 

Hopefully helps.

 

Review Cisco Networking for a $25 gift card