cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
352
Views
0
Helpful
5
Replies

SD-WAN

rajesh4
Level 1
Level 1

Dear Team,

1) Head Office --- Firepower 1010 firewall

2) Branch office --- Firepower 1010 firewall 

Requirement below:-  

Only few URL's  traffic burst out  in branch office ISP and remaining all application or internet access and internal server all traffic burst out from Head Office

This is possible, then please share the KB-Article.

 

5 Replies 5

Sorry can ypu more elaborate 

MHM

Hi,

We have one Head Office and five Branch Office's and Now we are planning only specific url's traffic burst out via Branch office ISP and Internal server and Internet traffic burst out via Head Office.

 

FW in SWDAN  have different positions and role' 

SDWAN can config under FW so FW need to open port for dtls/tls/ipsec and also if you use ssl policy then you must not decrypt ssl.

If SDWAN run DAI and it behind FW then additional to port open you need to allow traffic from internal to internet.

If FW use in HQ abd you use net service then this need design to allow traffic ingress and egress of FW (FW inspect traffic between branchs)

MHM

@Rob Ingram 

Noted, thanks for update and i am checking internally and once we have setup done and update you on same. 

Review Cisco Networking for a $25 gift card