cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
1037
Views
8
Helpful
11
Replies

connect 2 Cisco firepower 1010 nbut no internet

can someone help me,i configure 2 cisco firepower 1010,1 for router and the other for firewall,i can get internet from router device when i plug the rj45 to router,but i cant get internet when i do to firewall,please help me,thank you

1 Accepted Solution

Accepted Solutions

first of all,thank you for @MHM Cisco World helping and reach out the problem, i already solve the problem,im disable one of nat that cause the problem, 

bayuadibwiraprana1_0-1705853373045.png

outside to firewall 0.0.0.0/0(objamz) to objsrcnet(to one of the host),i cant put the ip  

View solution in original post

11 Replies 11

Friend I dont know how you use 192.168.1.0 to access internet' this IP is private IP and not accept in Interent public IP.

MHM 

Its from isp and the isp distribute it to private ip

Ok' 

Then ISP know only 192.168.1.0 subnet' all other subnet behind Router FW dont know it.

You need then NAT in router FW

note you need acl permit any any from inside zone to outside zone.

MHM

I already give nat and acl, you can see the document that i attach, the is problem when i ping 8.8.8.8 from the cisco firepower 1010(works as firewall) it "request time out" And cant get internet

let start with FW (router)
you config two interface and I see three ZONE ??
can you more elaborate named the interface and zone you use in FW (router)
thanks 
MHM

okey sir,

FW(router) security zone

bayuadibwiraprana1_0-1705458727914.png

toswitch eth2,inside vlan1,outside eth1

 

 

from your topology there are two link in FW (router) one to FW and other to internet ?
you need to specify the exact interface and zone in your NAT and ACL 
MHM

sir i screenshot router nat & cl, and firewall nat & acl

I think it easy for both to clarify it in topology 
since I see LAN and toSwitch and OUTside and I dont get for which this interface use 

Screenshot (87).png

first of all,thank you for @MHM Cisco World helping and reach out the problem, i already solve the problem,im disable one of nat that cause the problem, 

bayuadibwiraprana1_0-1705853373045.png

outside to firewall 0.0.0.0/0(objamz) to objsrcnet(to one of the host),i cant put the ip  

you are so welcome friend 
have a nice day
MHM