06-16-2022 10:04 AM
Hi,
We would like to add a policy for other VPN users to allow access to a specific internal device. I have not been able to find any documentation on how to do this. Could anyone provide the procedures or documentation for this? It would be greatly appreciated.
Thanks,
Quintin
06-16-2022 10:14 AM
To assists better we need to know - what hardware is this ? ASA with Firepower or FTD ?
what policy you looking to create ? give some example.
06-17-2022 09:20 AM
06-21-2022 06:09 AM
Hi,
We're using Cisco FTD 2110 any direction would be most appreciated.
Thanks,
06-21-2022 02:57 PM
06-16-2022 12:46 PM
06-22-2022 01:30 AM
Either its a site-to-site VPN tunnel or if its Anyconnect VPN. for both setup you have define a NAT exemption right. all you need doing is go to FMC (If you using FMC Console)--Policies->Access Control Policy--->select your policy-->once you in your policy setup and new rule. most probably you will be doing INSIDE TO OUTSIDE zone. In network Tab call your NAT object network you used. here go to Applications/Ports and define what you required them to allow.
And do not forget to set the rule action as ALLOW.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide