Brksec 3580
Brksec 3580
Brksec 3580
#CiscoLive
Cisco Webex App
Questions?
Use Cisco Webex App to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install the Webex App or go directly to the Webex space Enter your personal notes here
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
About your • Costa Rica / Texas
Speaker • 13+ years of experience
• TAC, Advanced Services, CSS
• CCIE Security / CISSP®
Customer Success
Specialist
BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
• Introduction
• Virtual Routing and Forwarding
• Configuring VRF
Agenda • Configuring Routing Protocols
• Troubleshooting VRF
• Conclusion
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Introduction
Virtual Routing
and Forwarding
Why Virtual Routers/Routing?
• Separate Routing/Forwarding tables
• VRF-Lite
• Overlapping IP address
• Multi-Virtual Router Support (FXOS + VRF =Multi-Context use cases)
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Advantages (FTD Version 6.6+)
• Routing segregation on FTD
• Overlapping IP address on FTD interfaces
• Connection events (ingress/egress virtual router)
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
VRF Support
Device Maximum Virtual Routers
ASA 10-20
Virtual FTD 30
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Routing Policies
Policies Global VRF User VRF
Static Route ✓ ✓
OSPFv2 ✓ ✓
OSPFv3 ✓ X
RIP ✓ X
BGPv4 ✓ ✓
BGPv6 ✓ ✓ (7.1+)
IRB (BVI) ✓ ✓
EIGRP ✓ X
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Overlapping Networks – Feature Support
Policies Non-Overlapping Overlapping Networks
Routing & IRB ✓ ✓
AVC ✓ ✓
SSL Decryption ✓ ✓
Intrusion and Malware
Detection (IPS and File ✓ ✓
Policy)
VPN ✓ ✓
Malware Event Analysis
(Host Profiles, IoC, File ✓ X
Trajectory)
Threat Intelligence (TID) ✓ X
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Use case #1 – Service Provider
• Separate routing tables
VRF_A VRF_B
Customer B
Customer A
• Overlapping Networks
• Non-Overlapping Networks
ISP
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Use case #2 – Enterprise
• Connectivity between VRFs (Route Leaking)
VRF_A VRF_B
Department B
Department A
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Use case #3 – Multi-Instance and VRF
• Connectivity between VRFs in a Multi-Instance Environment
VRF_A VRF_B
Department B
Department A
FTD Instance
• BGP (7.1+)
Firepower4100/9300
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Configuring VRF
Demo 1: VRF configuration on FMC
VRF configuration on FMC
Subtitle
• Device > Device Management > FTD
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
VRF configuration on FMC
Subtitle
• Routing > Manage Virtual Routers > Add Virtual Router
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
VRF configuration on FMC
• Add a new Virtual Router
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
VRF configuration on FMC
• Assign interfaces to VRF
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
VRF configuration on FMC
• Verify VRF assignment under “Interfaces”
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
VRF configuration on FMC
• Deploy changes
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
VRF configuration on FMC
• Deploy changes
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Access Control Policy VRF- Aware
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Access Control Policy VRF- Aware
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Access Control Policy VRF- Aware
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
NAT Policy VRF- Aware
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
NAT Policy VRF- Aware
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
NAT Policy VRF- Aware – Overlapping Networks
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Demo 2: Configuring VRF on FDM
VRF configuration on FDM
• Routing > View Configuration
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
VRF configuration on FDM
Subtitle
• Routing > Add Multiple Virtual Routers
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
VRF configuration on FDM
• Create First Custom Virtual Router
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
VRF configuration on FDM
• Add a new Virtual Router and assign interfaces
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
VRF configuration on FDM
• Deploy changes
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
VRF configuration on FDM
• Verified deployed changes
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Configuring Routing
Protocols
Demo 3: Configuring Static
Routing on FMC
Static Routing on FMC
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Static Routing on FMC
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Static Routing on FMC
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Static Routing on FMC
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Static Routing on FMC – Verify Configuration
• VRF_Sales > _Routes
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Demo 4 : Configuring BGP on
FMC
Border Gateway Protocol (BGP) on FMC
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Border Gateway Protocol (BGP) on FMC
• Routing > Desired VRF> BGP > IPv4
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Border Gateway Protocol (BGP) on FMC
• Routing > Desired VRF> BGP > IPv4 > Neighbor
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Border Gateway Protocol (BGP) on FMC
• Routing > Manage Virtual Routers> Desired VRF > Route | BGP
Summary
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Demo 5: Configuring OSPF on FMC
OSFP on FMC
• Routing > Desired VRF> OSPF
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
OSFP on FMC
• Add a Neighbor
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
OSFP on FMC
• Save and deploy changes
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
OSFP on FMC
• Routing > Manage Virtual Routers > route | OSPF Summary
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Demo 6: Configuring
BGP on FDM
Border Gateway Protocol (BGP) on FDM
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Border Gateway Protocol (BGP) on FDM
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Border Gateway Protocol (BGP) on FDM
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Border Gateway Protocol (BGP) on FDM
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Border Gateway Protocol (BGP) on FDM
BGP Object
• Save and Deploy changes
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Border Gateway Protocol (BGP) on FDM
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Demo 7: Configuring OSPF on FDM
OSPF on FDM
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
OSPF on FDM
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
OSPF on FDM
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Troubleshooting VRF
Troubleshooting - Commands
Configuration Verification
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Troubleshooting - Commands
Troubleshooting Verification
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Troubleshooting Scenario #1 - BGP
• BGP won’t come up
VRF_Sales
10.10.10.0/24
.221 .32
AS 65536
AS 65536
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Demo 8: Troubleshooting
Scenario #1 - BGP
Troubleshooting Scenario #1 - BGP
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Troubleshooting Scenario #1 - BGP
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Troubleshooting Scenario #1 - BGP
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Troubleshooting Scenario #1 - BGP
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Troubleshooting Scenario #2
• Connectivity between VRFs (Route Leaking)
VRF_Sales VRF_Engineering
172.16.10.3/24
172.16.20.3/24
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Demo 9: Troubleshooting Scenario #2
Troubleshooting Scenario #2 – Route Leak
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Troubleshooting Scenario #2 – Route Leak
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Troubleshooting Scenario #2 – Route Leak
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Troubleshooting Scenario #2 – Route Leak
packet-tracer input engineering icmp 172.16.2.3 8 0 172.16.1.3
Phase: 3
Type: INPUT-ROUTE-LOOKUP
Subtype: Resolve Egress Interface
Result: ALLOW
Config:
Additional Information:
Found next-hop 0.0.0.0 using egress ifc Sales(vrfid:1)
Phase: 4
Type: UN-NAT
Subtype: static
Result: ALLOW
Config:
nat (Sales,Engineering) source static Sales_Net Sales_Net destination static Eng_Network Eng_Network route-
lookup
Additional Information:
NAT divert to egress interface Sales(vrfid:1)
Untranslate 172.16.1.3/0 to 172.16.1.3/0
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Troubleshooting Scenario #2 – Route Leak
Phase: 18
Type: INPUT-ROUTE-LOOKUP-FROM-OUTPUT-ROUTE-LOOKUP
Subtype: Resolve Preferred Egress interface
Result: ALLOW
Config:
Additional Information:
Found next-hop 172.16.1.3 using egress ifc Sales(vrfid:1)
Result:
input-interface: Engineering(vrfid:2)
input-status: up
input-line-status: up
output-interface: Sales(vrfid:1)
output-status: up
output-line-status: up
Action: allow
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Troubleshooting Scenario #2 – Route Leak
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Conclusion
• Enhanced FTD’s routing
capabilities.
• Secure way of segmenting
routing table and expands our
FTD deployment options
Conclusions
• Take advantage of Meet the
expert
BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Technical Session Surveys
• Attendees who fill out a minimum of four
session surveys and the overall event
survey will get Cisco Live branded socks!
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
• Visit the Cisco Showcase
for related demos
BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Pay for Learning with
Cisco Learning Credits
Cisco Learning and Certifications (CLCs) are prepaid training
vouchers redeemed directly
From technology training and team development to Cisco certifications and learning with Cisco.
plans, let us help you empower your business and career. www.cisco.com/go/certs
Here at the event? Visit us at The Learning and Certifications lounge at the World of Solutions
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Thank you
#CiscoLive
#CiscoLive