03-13-2022 03:52 AM
I have a customer who is using Cisco Anyconnect for user remote VPN network access on an FTD appliance. The FTD appliance is the secondary firewall on the edge of the network and is connecting to their primary firewall. They would like to route all Anyconnect VPN traffic including Internet traffic through the primary firewall which is connected on the inside interface of the FTD appliance.
Is it a way I can point the default route to the primary firewall that is on the inside interface but still allow remote VPN access on the outside interface of the FTD appliance?
Solved! Go to Solution.
03-13-2022 06:54 AM
Look for Step 10 on page 4 of the document provided by @Rob Ingram.
Another option is to place the Firepower with only one interface in a DMZ of the primary Firewall. Traffic flow would be the following:
03-13-2022 07:58 AM
Ok, great. Thanks for the help
03-13-2022 03:58 AM
@Maurice Ball if using an FMC to manage the FTD you can select the "tunneled" option, which will define a separate default route for VPN tunneled traffic, routing the traffic to the specified next hop - which maybe different to the default route.
However this option does not exist as of version 7.1 when managing the FTD local using FDM.
03-13-2022 05:55 AM
Sorry, but I am not understanding how to make this work based on the article. The VPN user's internal traffic and Internet traffic are both considered to be data traffic.This article states that you are able to create two default routes one for data and one for management traffic. I do not understand how I can use that configuration in this deployment. Could you please provide more details on how that would work?
03-13-2022 06:54 AM
Look for Step 10 on page 4 of the document provided by @Rob Ingram.
Another option is to place the Firepower with only one interface in a DMZ of the primary Firewall. Traffic flow would be the following:
03-13-2022 07:58 AM
Ok, great. Thanks for the help
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide