cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
10249
Views
0
Helpful
2
Replies

Same Ingress & Egress Zone on Firepower

Hi Support Community

 

I was wondering if someone here can answer my question. I have a customer that has a Cisco 4140 Firepower Appliance and this is doing Data Centre segmentation. Does the Firepower Appliances support sending traffic out the same Zone that it was received on and is there a command that one must run for this.

 

I remember in the ASA days one had to configure the "same-security-traffic permit inter-interface" and "same-security-traffic permit intra-interface" commands in order to achieve  traffic being sent between interfaces of the same security level without being controlled by an Access-List. 

 

So, does the Firepower Appliances (not ASA with Firepower Modules) support this feature and is it supported by default or does one need to configure it to be supported??

2 Replies 2

Dennis Mink
VIP Alumni
VIP Alumni

If you will be using for arguments sake the "inside" interface to receive traffic on (because for instance a default route points to it). and the send the traffic out the same inside interface destined for another subnet. that sort of makes the firewall a router, with no ACL applied. I cant see why that wont work?  any reason why you wouldnt be using subinterfaces?

Please remember to rate useful posts, by clicking on the stars below.

Bogdan Nita
VIP Alumni
VIP Alumni

"same-security-traffic is not applicable on FTD. Traffic between FTD interfaces (inter) and hairpinning (intra) is allowed by default"

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200908-configuring-firepower-threat-defense-int.html

 

HTH

Bogdan

Review Cisco Networking for a $25 gift card