11-21-2021 11:39 AM
11-21-2021 12:25 PM
11-23-2021 12:01 PM
NAT is proper configured? Static default route or dynamic route is in place?
Ping to ISP works? Ping outside internet to 8.8.8.8 works?
Like stated before did you check if ACP might be blocking the traffic? Maybe it did not migrate all ACP as expected.
11-23-2021 12:46 PM
Please provide more information on how your network is physically and logically setup (are you using portchannels, subinterfaces, what VLANs correspond to what interface, etc.)
And please check the following:
1. Make sure there are no outstanding deployments in the FMC
2. Make sure you have a Dynamic NAT configured from both Inside and DMZ interfaces towards the Outside interface
3. Make sure that logging is enabled for the ACP rules, and if / when it is enabled check Analysis > Connection Events to see if traffic is being blocked
4. If all the above looks fine, log into the FTD CLI and ping your ISP IP (default route IP), if that is successful, ping 8.8.8.8
5. If all these tests are successful go to the FTD CLI (at the > prompt) and issue the command system support trace
Make sure to enable system support firewall-engine-debug when asked.
Enter the source IP of a test PC you will use to generate traffic to the internet
Enter the destination IP you are testing towards
*** for all other fields just press enter ***
The last step should show if traffic is being dropped by either Snort or a firewall rule, if the traffic is reaching the firewall.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide