cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1406
Views
0
Helpful
2
Replies

Firepower Bidirection of AC rules

Hi Everyone,

Can somebody clarify my if I put access control rule in AC policy in firepower that allow traffic from A to B does it automatically permit traffic from B to A? I mean, do I need a new rule that will allow opposite direction?

for example, let's have a rule that allow 192.168.1.0/24 network to 192.168.2.0/24. 

If i try to ping from .2.0 to .1.0 will it be allowed?

Best regards,
Stefan

2 Replies 2

Hi @StefanStankovic2195 

If you permit traffic from A to B and A initiates the communication, the return traffic from B will be permitted. You would need a rule from B to A if B initiates the communication.

 

HTH

The return traffic will be allowed.  However, if you ping you need to make sure that icmp inspect command is present in the policy-map configuration or the return traffic will not be allowed.  TCP will be "inspected" and allowed.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card