Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Good day all,I am having a strange issue that have be baffled for the past few days. I have a S2S Policy-based VPN setup between 2 sites. One site has a FPR2110 (software: 7.4.2-172) and the other a FPR3110 (software: 7.6.6-115). I have dual ISPs on...
Good day all. This is my first post on here. I have been fighting up with an issue that is happening with S2S Policy-Based VPN. I have a new Firepower 3110 (FTD) that I am managing through FMC. I am setting up S2S VPNs to our remote offices. FPR3110 ...
Yes. The counters are increasing with show asp dropcapture ASP type asp-drop all match ip 192.168.0.0 255.255.255.0 192.168.75.0 255.255.255.0 shows no result on 2110However, on the 3110 capture ASP type asp-drop all match ip 192.168.75.0 255.255.255...
Yes, NAT exemption is set for both ISPs. See below for packet-tracer results (All phases are ALLOW).__________________________________> packet-tracer input lan1 icmp 192.168.75.50 8 0 192.168.0.6Phase: 1Type: ACCESS-LISTSubtype:Result: ALLOWElapsed t...
Hi Rob,I've set NAT exemption for the inside interface in the S2S VPN connection profile. I also set 'sysopt connection permit-vpn' using Flexconfig. This way, no ACLs or NAT rules are required. It works fine when using ISP1 on the FPR3110 without an...
@Rob Ingram, You've pointed me in the correct direction. The PC's firewall is being managed by ESET Endpoint Security that is installed. Once I disabled ESET, it works fine. Seems like I'll have to configure exemptions in ESET to allow traffic from o...