09-19-2022 05:52 AM
Firepower is setup with ASA behind it. Need to setup IPSec between ASA and Outside/internet JuniperFW. I can see IKE and ISAKMP packets, but no ESP. Is this even possible:-
Use FMC to traverse IPSEC for an internal ASA
Any inherent policy in FMC that blocks ESP
09-19-2022 10:02 AM
If your default action in the Firepower Access Control Policy is to Block then the ESP (protocol 50) will be blocked.
The typical recommendation for such a use case is to put the source and destination of the IPsec tunnel in a prefilter policy rule with action of Fastpath. That way you skip all other ACP rules and Snort altogether.
09-19-2022 10:05 AM
https://tungdt.net/configure-site2site-vpn-between-juniper-srx-and-cisco-asa-firewalls/
M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide