08-14-2024 04:44 AM
Dear Team,
1) Head Office --- Firepower 1010 firewall
2) Branch office --- Firepower 1010 firewall
Requirement below:-
Only few URL's traffic burst out in branch office ISP and remaining all application or internet access and internal server all traffic burst out from Head Office
This is possible, then please share the KB-Article.
08-14-2024 05:15 AM
Sorry can ypu more elaborate
MHM
08-14-2024 05:25 AM
Hi,
We have one Head Office and five Branch Office's and Now we are planning only specific url's traffic burst out via Branch office ISP and Internal server and Internet traffic burst out via Head Office.
08-14-2024 11:02 AM
FW in SWDAN have different positions and role'
SDWAN can config under FW so FW need to open port for dtls/tls/ipsec and also if you use ssl policy then you must not decrypt ssl.
If SDWAN run DAI and it behind FW then additional to port open you need to allow traffic from internal to internet.
If FW use in HQ abd you use net service then this need design to allow traffic ingress and egress of FW (FW inspect traffic between branchs)
MHM
08-14-2024 05:24 AM
@rajesh4 FTD does have some SD-WAN capabilities that could meet your requirements, but only if managed by FMC.
You can also refer to the Cisco Live presentation - Optimizing Security and Agility: Leveraging SD-WAN with Cisco Secure Firewall - BRKSEC-2086
08-16-2024 02:29 AM
Noted, thanks for update and i am checking internally and once we have setup done and update you on same.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide