cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2916
Views
0
Helpful
3
Replies

Tips to pass tunnel GRE over Firepower FTD

claudiom17
Level 1
Level 1

Hello team, I am trying to pass one GRE tunnel over two Cisco Firepower 1120 Theat Defense version 7.3.1-19 working as active/stand by. The devices are stand alone and those are not working or manged by FMC. How can I assure the traffic can be allowed in the tunnel GRE communication between one SD-WAN veloclud device in the inside and one Zscaler in the outside?

I have created an ACL allowing the GRE protocol from inside to outside and viceversa?

Do you know any other way? Pre-filtering is not allowing in this version, only in FMC.

3 Replies 3

Mark Elsen
Hall of Fame
Hall of Fame

 

       - FYI : https://www.networkingwithehsan.com/gre-tunnel-in-ftd

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi @claudiom17,

This is the limitation of FDM over FMC. Most often, GRE should be addressed via prefilter policy, which is not supported on FDM. It is in FDM admin guide.

You can try to allow it within standard Access Control policy, but if it is not per RFC, it must be bypassed via prefilter.

Kind regards,

Milos

dave wolfendale
Level 1
Level 1

Use "Trust" as the access rule action.

This is the equivalent of FastPath.

I put all sorts in the access but this is the only way.

Of course, the flaw is that it does not get inspected - welcome to the wonder of FirePower.

Review Cisco Networking for a $25 gift card