cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
942
Views
1
Helpful
4
Replies

FMC not seeing HTTP/HTTPS traffic

Knassi
Level 1
Level 1

So i am trying to find out why i am unable to get on a website. I do not see any blocks in the FMC, i don't even see any traffic related to that IP. But when i try to ping it, i see the ICMP traffic in the FMC. Has anyone seen this kind of problem?

1 Accepted Solution

Accepted Solutions

@Knassi are you logging traffic?

From the CLI of the FTD run "system support firewall-engine-debug" filter on the source ip and/or destination and generate traffic. The output on the console will confirm traffic is passing through the firewall and tell you which rule traffic is matching.

View solution in original post

4 Replies 4

@Knassi are you logging traffic?

From the CLI of the FTD run "system support firewall-engine-debug" filter on the source ip and/or destination and generate traffic. The output on the console will confirm traffic is passing through the firewall and tell you which rule traffic is matching.

Knassi
Level 1
Level 1

So i have been able to pull some traffic and there is only one rule match, the very last one that actually allows any any. How can an "allow any any "rule be blocking traffic?

Knassi
Level 1
Level 1

I think the intrusion prevention policy dropped the packet before it hit the access control policy rule. Thank you all

I follow your Q, if am right you run the below 
you make management connect to INside then to FMC ? 
this not recommend from Cisco 
that why your management traffic hit the ACP of FTD 

Screenshot (468).png

Review Cisco Networking for a $25 gift card