11-08-2024 12:39 PM
I have setup a Route Based Site-Site Tunnel with Cisco Umbrella. Tunnel comes up fine. My issue is I'm using Policy Based Routing because I only want 80/443 traffic to go over the tunnel.
Packet tracer shows that PBR-Lookup matches the ACL and identifies the VTI, but the FTD doesn't resolve the egress to the VTI...but to the outside interface.
So the traffic isn't flowing over the tunnel to Umbrella, which is confusing since it is matching the ACL used by the PBR.
show route-map
route-map FMC_GENERATED_PBR_1730396602092, permit, sequence 5
Match clauses:
ip address (access-lists): Umbrella_Tunnel_Allow_Mailroom
Set clauses:
adaptive-interface cost Umbrella-VTI (0)
11-08-2024 06:30 PM
11-13-2024 06:53 AM
Thank you. Used this and followed the instructions to the letter. Still, the traffic in ACL not being sent to VTI interface.
11-09-2024 12:58 AM
I am sure you have all routing in place verify and check the below configuration guide :
11-10-2024 01:48 AM
Set clauses:
adaptive-interface cost Umbrella-VTI (0)
Set your clause / next-hop to be +1 of your own VTI address towards Umbrella.
11-13-2024 06:52 AM
Not sure what you mean.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide