cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2167
Views
0
Helpful
3
Replies

Tips to pass tunnel GRE over Firepower FTD

claudiom17
Level 1
Level 1

Hello team, I am trying to pass one GRE tunnel over two Cisco Firepower 1120 Theat Defense version 7.3.1-19 working as active/stand by. The devices are stand alone and those are not working or manged by FMC. How can I assure the traffic can be allowed in the tunnel GRE communication between one SD-WAN veloclud device in the inside and one Zscaler in the outside?

I have created an ACL allowing the GRE protocol from inside to outside and viceversa?

Do you know any other way? Pre-filtering is not allowing in this version, only in FMC.

3 Replies 3

marce1000
Hall of Fame
Hall of Fame

 

       - FYI : https://www.networkingwithehsan.com/gre-tunnel-in-ftd

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi @claudiom17,

This is the limitation of FDM over FMC. Most often, GRE should be addressed via prefilter policy, which is not supported on FDM. It is in FDM admin guide.

You can try to allow it within standard Access Control policy, but if it is not per RFC, it must be bypassed via prefilter.

Kind regards,

Milos

dave wolfendale
Level 1
Level 1

Use "Trust" as the access rule action.

This is the equivalent of FastPath.

I put all sorts in the access but this is the only way.

Of course, the flaw is that it does not get inspected - welcome to the wonder of FirePower.

Review Cisco Networking for a $25 gift card