cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
989
Views
0
Helpful
6
Replies

FirePower - Adding a Policy for VPN users

Quintin.Mayo
Level 3
Level 3

Hi,

 

We would like to add a policy for other VPN users to allow access to a specific internal device. I have not been able to find any documentation on how to do this.  Could anyone provide the procedures or documentation for this?  It would be greatly appreciated. 

 

Thanks,

Quintin

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

To assists better we need to know - what hardware is this ? ASA with Firepower or FTD ?

what policy you looking to create ?  give some example.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi,
Thanks for your response. We're using Cisco FTD 2110 any direction would be most appreciated.


#- Please type your reply above this line -##

________________________________
Important Notice: This email message and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you are not the named addressee, you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system. Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of Core BTS. Core BTS specifically disclaims liability for any damage caused by any virus transmitted by this email.

Hi,

We're using Cisco FTD 2110 any direction would be most appreciated.

 

Thanks,

 

 

Either its a site-to-site VPN tunnel or if its Anyconnect VPN. for both setup you have define a NAT exemption right. all you need doing is go to FMC (If you using FMC Console)--Policies->Access Control Policy--->select your policy-->once you in your policy setup and new rule. most probably you will be doing INSIDE TO OUTSIDE zone. In network Tab call your NAT object network you used. here go to Applications/Ports and define what you required them to allow.

 

And do not forget to set the rule action as ALLOW.

please do not forget to rate.