cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
662
Views
0
Helpful
3
Replies

Inside another inside interface not triggering firepower signatures

babiojd01
Level 1
Level 1

I can't seem to get firepower to alert on communication from 1 inside interface to another. I only get it to trigger when I go from inside to outside. Any thoughts? I even modified the HOME_NET to be any. I have the sfr policy global and the 2 interfaces are 1 inside interface and a subinterface off of that. 

3 Replies 3

Philip D'Ath
VIP Alumni
VIP Alumni

So the global policy only applies if an interface policy does not apply.

I normally apply the sfr policy to all interfaces except the outside interface (at least, every interface I want inspected), and let the global inspection policy (not using sfr) act on that.

Hi Philip,

So you do
service-policy sfr-service-policy interface inside

service-policy sfr-service-policy interface dmz

etc?

Yes, that is my preferred deployment approach.

This differs from the way Cisco shows in their documents.  The nice thing about this way is you can still use FTP fixups and the like.

Review Cisco Networking for a $25 gift card