05-20-2021 06:52 AM
Hello!
How can I restrict access for some external IP addresses or may be gelocation to RA VPN address on FTD?
I have FTD controlled by FMC version 6.6.1. Prefilter and access control policy didn't affected.
Thanks.
Solved! Go to Solution.
05-20-2021 06:59 AM
Pre-filter and ACP control traffic "through" the FTD, not for connections "to" the FTD, such as RAVPN.
So you cannot use Geolocation to control access to the FTD. You'd have to purchase another FTD and in place in front of your RAVPN FTD's, then the traffic would be going through the FTD and you can then use an ACP with geolocation.
Alternatively you could filter by IP address either on the upstream router or use flexconfig to apply a control plane ACL.
06-01-2021 01:47 AM
Starting with Firepower (and FMC) 7.0 you could use Dynamic Access Policies to block known IP addresses from trying to VPN to your network. GEO blocking is sadly not possible.
See this enhancement here: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs65322/
05-20-2021 06:59 AM
Pre-filter and ACP control traffic "through" the FTD, not for connections "to" the FTD, such as RAVPN.
So you cannot use Geolocation to control access to the FTD. You'd have to purchase another FTD and in place in front of your RAVPN FTD's, then the traffic would be going through the FTD and you can then use an ACP with geolocation.
Alternatively you could filter by IP address either on the upstream router or use flexconfig to apply a control plane ACL.
06-01-2021 01:47 AM
Starting with Firepower (and FMC) 7.0 you could use Dynamic Access Policies to block known IP addresses from trying to VPN to your network. GEO blocking is sadly not possible.
See this enhancement here: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs65322/
01-30-2023 02:55 PM
Are you sure it requires 7.0? Unless something changed, looks like it's just an ACL and Flexconfig per your link..?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: