Download Print this page

Cisco Firepower 1010 Getting Started page 32

Hide thumbs Also See for Firepower 1010:

Advertisement

Configuration Basics
Setting
Access control policy.
NAT
Configuration Basics
The following topics explain the basic methods for configuring the device.
Configuring the Device
When you initially log into FDM, you are guided through a setup wizard to help you configure basic settings.
Once you complete the wizard, use the following method to configure other features and to manage the device
configuration.
If you have trouble distinguishing items visually, select a different color scheme in the user profile. Select
Profile from the user icon drop-down menu in the upper right of the page.
Procedure
Step 1
Click Device to get to the Device Summary.
Getting Started
32
Configuration
A rule trusting all traffic from the inside_zone to the outside_zone.
This allows without inspection all traffic from users inside your
network to get outside, and all return traffic for those connections.
The default action for any other traffic is to block it. This prevents
any traffic initiated from outside to enter your network.
Firepower 4100/9300: There are no pre-configured access rules.
ISA 3000: A rule trusting all traffic from the inside_zone to the
outside_zone, and a rule trusting all traffic from the outside_zone
to the inside_zone. Traffic is not blocked. The device also has
rules trusting all traffic between the interfaces in the inside_zone
and in the outside_zone. This allows without inspection all traffic
between users on the inside, and between users on the outside.
An interface dynamic PAT rule translates the source address for
any IPv4 traffic destined to the outside interface to a unique port
on the outside interface's IP address.
There are additional hidden PAT rules to enable HTTPS access
through the inside interfaces, and routing through the data
interfaces for the management address. These do not appear in
the NAT table, but you will see them if you use the show nat
command in the CLI.
Firepower 4100/9300: NAT is not pre-configured.
ISA 3000: NAT is not pre-configured.
Getting Started
Explicit, implied, or default
configuration
Implied.
Implied.

Advertisement

loading