08-03-2018 08:33 PM - edited 03-12-2019 04:07 AM
I have a FP2110- 6.2.2 with 2 sub-interfaces (vlan11 and vlan99) on physical interface 2. I have a C9300 connected trunked to the FP and have a 2 laptops connected to switch ports that are assigned to the vlan 11 and vlan 99.
FTD vlan 99 - 192.168.10.1. (laptop 192.168.10.2)
FTD vlan 11 - 192.168.11.1 (laptop 192.168.11.2)
FTD Outside 172.16.1.1
Cat 9300 - Vlan11 and vlan 99 assigned to ports 3 and 5 respectively.
Remote Router -172.16.1.2
Router loopback 192.168.168.1
My laptop on vlan 99 can ping the FTD interface, Remote Router and Router loopback with no issues, but it can't ping the laptop on vlan 11. I can ping the laptop from the router loopback with no issues.
Laptop on vlan 11 can't ping it's GW of 192.168.11.1 or anything else.
I have an access policy for ANY ANY ANY ANY across the board for testing.
Any idea why the traffic will not pass on vlan 11?
08-04-2018 11:05 PM
08-05-2018 08:55 AM
1st Problem Solved. Bad ethernet dongle on my MacBook. Sheesh! Now if I have the default Access Policy set to allow, everything can ping everything as expected.
Locking down via ACL, im creating Zones for each VLAN and then creating appropriate policy to allow bidirectional traffic between zones.
One thing I noticed that after creating the ACL's to allow the VLAN's to communicate with no issues, the laptops can't communicate across the WAN, so I've got to play with that a bit today. Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide