Brksec 3580

Download as pdf or txt
Download as pdf or txt
You are on page 1of 89

#CiscoLive

Firepower Threat Defense


Virtual Routing and
Forwarding (VRF)

Luis Silva Benavides – Customer Success Specialist


@LuisSilva_1990
BRKSEC-3580

#CiscoLive
Cisco Webex App

Questions?
Use Cisco Webex App to chat
with the speaker after the session

How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install the Webex App or go directly to the Webex space Enter your personal notes here

4 Enter messages/questions in the Webex space

Webex spaces will be moderated https://ciscolive.ciscoevents.com/ciscolivebot/#BRKSEC-3580

by the speaker until June 17, 2022.

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
About your • Costa Rica / Texas
Speaker • 13+ years of experience
• TAC, Advanced Services, CSS
• CCIE Security / CISSP®

Customer Success
Specialist
BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
• Introduction
• Virtual Routing and Forwarding
• Configuring VRF
Agenda • Configuring Routing Protocols
• Troubleshooting VRF
• Conclusion

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Introduction
Virtual Routing
and Forwarding
Why Virtual Routers/Routing?
• Separate Routing/Forwarding tables
• VRF-Lite
• Overlapping IP address
• Multi-Virtual Router Support (FXOS + VRF =Multi-Context use cases)

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Advantages (FTD Version 6.6+)
• Routing segregation on FTD
• Overlapping IP address on FTD interfaces
• Connection events (ingress/egress virtual router)

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
VRF Support
Device Maximum Virtual Routers

ASA 10-20

Firepower 1000* 5-10 *1010 (7.2+)

Firepower 2100 10-40

Firepower 3100 15-100

Firepower 4100 60-100

Firepower 9300 60-100

Virtual FTD 30

ISA 3000 10 (7.0+)

Configuration Guide No License required

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Routing Policies
Policies Global VRF User VRF

Static Route ✓ ✓

OSPFv2 ✓ ✓

OSPFv3 ✓ X

RIP ✓ X

BGPv4 ✓ ✓

BGPv6 ✓ ✓ (7.1+)

IRB (BVI) ✓ ✓

EIGRP ✓ X

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Overlapping Networks – Feature Support
Policies Non-Overlapping Overlapping Networks
Routing & IRB ✓ ✓

AVC ✓ ✓

SSL Decryption ✓ ✓
Intrusion and Malware
Detection (IPS and File ✓ ✓
Policy)
VPN ✓ ✓
Malware Event Analysis
(Host Profiles, IoC, File ✓ X
Trajectory)
Threat Intelligence (TID) ✓ X

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Use case #1 – Service Provider
• Separate routing tables

VRF_A VRF_B

Customer B
Customer A

• Overlapping Networks

• Non-Overlapping Networks

ISP

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Use case #2 – Enterprise
• Connectivity between VRFs (Route Leaking)

VRF_A VRF_B

Department B
Department A

• Overlapping Networks • Static Routes

• Non-Overlapping Networks • NAT

Company • BGP (7.1+)

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Use case #3 – Multi-Instance and VRF
• Connectivity between VRFs in a Multi-Instance Environment
VRF_A VRF_B

Department B
Department A

FTD Instance

• Overlapping Networks • Static Routes

• Non-Overlapping Networks • NAT

• BGP (7.1+)
Firepower4100/9300
#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Configuring VRF
Demo 1: VRF configuration on FMC
VRF configuration on FMC
Subtitle
• Device > Device Management > FTD

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
VRF configuration on FMC
Subtitle
• Routing > Manage Virtual Routers > Add Virtual Router

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
VRF configuration on FMC
• Add a new Virtual Router

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
VRF configuration on FMC
• Assign interfaces to VRF

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
VRF configuration on FMC
• Verify VRF assignment under “Interfaces”

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
VRF configuration on FMC
• Deploy changes

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
VRF configuration on FMC
• Deploy changes

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Access Control Policy VRF- Aware

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Access Control Policy VRF- Aware

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Access Control Policy VRF- Aware

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
NAT Policy VRF- Aware

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
NAT Policy VRF- Aware

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
NAT Policy VRF- Aware – Overlapping Networks

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Demo 2: Configuring VRF on FDM
VRF configuration on FDM
• Routing > View Configuration

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
VRF configuration on FDM
Subtitle
• Routing > Add Multiple Virtual Routers

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
VRF configuration on FDM
• Create First Custom Virtual Router

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
VRF configuration on FDM
• Add a new Virtual Router and assign interfaces

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
VRF configuration on FDM
• Deploy changes

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
VRF configuration on FDM
• Verified deployed changes

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Configuring Routing
Protocols
Demo 3: Configuring Static
Routing on FMC
Static Routing on FMC

• Routing > Desired VRF > Static Route

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Static Routing on FMC

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Static Routing on FMC

• Save > Deploy Changes

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Static Routing on FMC

• Deploy > Deploy Changes

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Static Routing on FMC – Verify Configuration
• VRF_Sales > _Routes

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Demo 4 : Configuring BGP on
FMC
Border Gateway Protocol (BGP) on FMC

• Routing > General Settings> BGP

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Border Gateway Protocol (BGP) on FMC
• Routing > Desired VRF> BGP > IPv4

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Border Gateway Protocol (BGP) on FMC
• Routing > Desired VRF> BGP > IPv4 > Neighbor

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Border Gateway Protocol (BGP) on FMC
• Routing > Manage Virtual Routers> Desired VRF > Route | BGP
Summary

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Demo 5: Configuring OSPF on FMC
OSFP on FMC
• Routing > Desired VRF> OSPF

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
OSFP on FMC
• Add a Neighbor

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
OSFP on FMC
• Save and deploy changes

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
OSFP on FMC
• Routing > Manage Virtual Routers > route | OSPF Summary

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Demo 6: Configuring
BGP on FDM
Border Gateway Protocol (BGP) on FDM

• Routing > BGP General Settings

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Border Gateway Protocol (BGP) on FDM

• Create BGP General Settings Object

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Border Gateway Protocol (BGP) on FDM

• BGP General Settings

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Border Gateway Protocol (BGP) on FDM

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Border Gateway Protocol (BGP) on FDM
BGP Object
• Save and Deploy changes

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Border Gateway Protocol (BGP) on FDM

• Verify routing table and BGP neighbor

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Demo 7: Configuring OSPF on FDM
OSPF on FDM

• Create OSPF Object

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
OSPF on FDM

• Configure OSPF Object

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
OSPF on FDM

• Verify routing table

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Troubleshooting VRF
Troubleshooting - Commands
Configuration Verification

Global VRF User- Defined VRF All VRF


Show run route
Show run route
Show run route all
vrf <name>

Show run router


Show run router
vrf <name>
Show run router bgp|ospf Show run router bgp|ospf
Show run router bgp|ospf vrf <name> all

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Troubleshooting - Commands
Troubleshooting Verification

Global VRF User- Defined VRF All VRF


Show route Show route
Show route
static|ospf|bgp static|ospf|bgp
static|ospf|bgp
vrf <name> all
Show bgp|ospf vrf <name>
Show bgp|ospf [sub-
[sub-commands]
commands]

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Troubleshooting Scenario #1 - BGP
• BGP won’t come up

VRF_Sales

10.10.10.0/24

.221 .32

AS 65536
AS 65536

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Demo 8: Troubleshooting
Scenario #1 - BGP
Troubleshooting Scenario #1 - BGP

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Troubleshooting Scenario #1 - BGP

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Troubleshooting Scenario #1 - BGP

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Troubleshooting Scenario #1 - BGP

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Troubleshooting Scenario #2
• Connectivity between VRFs (Route Leaking)

VRF_Sales VRF_Engineering

172.16.10.3/24
172.16.20.3/24

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Demo 9: Troubleshooting Scenario #2
Troubleshooting Scenario #2 – Route Leak

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Troubleshooting Scenario #2 – Route Leak

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Troubleshooting Scenario #2 – Route Leak

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Troubleshooting Scenario #2 – Route Leak
packet-tracer input engineering icmp 172.16.2.3 8 0 172.16.1.3

Phase: 3
Type: INPUT-ROUTE-LOOKUP
Subtype: Resolve Egress Interface
Result: ALLOW
Config:
Additional Information:
Found next-hop 0.0.0.0 using egress ifc Sales(vrfid:1)

Phase: 4
Type: UN-NAT
Subtype: static
Result: ALLOW
Config:
nat (Sales,Engineering) source static Sales_Net Sales_Net destination static Eng_Network Eng_Network route-
lookup
Additional Information:
NAT divert to egress interface Sales(vrfid:1)
Untranslate 172.16.1.3/0 to 172.16.1.3/0

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Troubleshooting Scenario #2 – Route Leak

packet-tracer input engineering icmp 172.16.2.3 8 0 172.16.1.3

Phase: 18
Type: INPUT-ROUTE-LOOKUP-FROM-OUTPUT-ROUTE-LOOKUP
Subtype: Resolve Preferred Egress interface
Result: ALLOW
Config:
Additional Information:
Found next-hop 172.16.1.3 using egress ifc Sales(vrfid:1)

Result:
input-interface: Engineering(vrfid:2)
input-status: up
input-line-status: up
output-interface: Sales(vrfid:1)
output-status: up
output-line-status: up
Action: allow

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Troubleshooting Scenario #2 – Route Leak

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Conclusion
• Enhanced FTD’s routing
capabilities.
• Secure way of segmenting
routing table and expands our
FTD deployment options
Conclusions
• Take advantage of Meet the
expert

• Let's deploy it!

BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Technical Session Surveys
• Attendees who fill out a minimum of four
session surveys and the overall event
survey will get Cisco Live branded socks!

• Attendees will also earn 100 points


in the Cisco Live Game for every
survey completed.

• These points help you get on the


leaderboard and increase your chances
of winning daily and grand prizes.

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
• Visit the Cisco Showcase
for related demos

• Book your one-on-one


Meet the Engineer meeting

• Attend the interactive education


with DevNet, Capture the Flag,
Continue and Walk-in Labs

your education • Visit the On-Demand Library


for more sessions at
www.CiscoLive.com/on-demand

BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Pay for Learning with
Cisco Learning Credits
Cisco Learning and Certifications (CLCs) are prepaid training
vouchers redeemed directly
From technology training and team development to Cisco certifications and learning with Cisco.
plans, let us help you empower your business and career. www.cisco.com/go/certs

Learn Train Certify


Cisco U. Cisco Training Bootcamps Cisco Certifications and
IT learning hub that guides teams Intensive team & individual automation Specialist Certifications
and learners toward their goals and technology training programs Award-winning certification
program empowers students
Cisco Digital Learning Cisco Learning Partner Program and IT Professionals to advance
Subscription-based product, technology, Authorized training partners supporting their technical careers
and certification training Cisco technology and career certifications
Cisco Guided Study Groups
Cisco Modeling Labs Cisco Instructor-led and 180-day certification prep program
Network simulation platform for design, Virtual Instructor-led training with learning and support
testing, and troubleshooting Accelerated curriculum of product,
technology, and certification courses Cisco Continuing
Cisco Learning Network Education Program
Resource community portal for Recertification training options
certifications and learning for Cisco certified individuals

Here at the event? Visit us at The Learning and Certifications lounge at the World of Solutions

#CiscoLive BRKSEC-3580 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Thank you

#CiscoLive
#CiscoLive

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy