Configure A Basic Security Policy - Cisco Firepower 1100 Getting Started Manual

Hide thumbs Also See for Firepower 1100:
Table of Contents

Advertisement

Threat Defense Deployment with the Management Center
For more troubleshooting information, see https://cisco.com/go/fmc-reg-error.

Configure a Basic Security Policy

This section describes how to configure a basic security policy with the following settings:
• Inside and outside interfaces—Assign a static IP address to the inside interface, and use DHCP for the
• DHCP server—Use a DHCP server on the inside interface for clients.
• Default route—Add a default route through the outside interface.
• NAT—Use interface PAT on the outside interface.
• Access control—Allow traffic from inside to outside.
To configure a basic security policy, complete the following tasks.
Configure Interfaces
Enable the threat defense interfaces, assign them to security zones, and set the IP addresses. Typically, you
must configure at least a minimum of two interfaces to have a system that passes meaningful traffic. Normally,
you would have an outside interface that faces the upstream router or internet, and one or more inside interfaces
for your organization's networks. Some of these interfaces might be "demilitarized zones" (DMZs), where
you place publically-accessible assets such as your web server.
A typical edge-routing situation is to obtain the outside interface address through DHCP from your ISP, while
you define static addresses on the inside interfaces.
The following example configures a routed mode inside interface with a static address and a routed mode
outside interface using DHCP.
outside interface.
Configure Interfaces, on page
Configure the DHCP Server, on page
Add the Default Route, on page
Configure NAT, on page
Allow Traffic from Inside to Outside, on page
Deploy the Configuration, on page
27.
30.
31.
33.
35.
36.
Cisco Firepower 1100 Getting Started Guide
Configure a Basic Security Policy
27

Advertisement

Table of Contents
loading

This manual is also suitable for:

Firepower 2100

Table of Contents