Overview
Provides instructions for configuring access control policies to allow traffic across a route-based site-to-site VPN using Firewall Management Center (FMC).
Before proceeding, ensure that the VTI interfaces on NGFW1 and NGFWBR1 nodes are associated to a new zone labeled as Tunnel_Zone.
Navigate to Policies > Access Control to review the access control policies. The following access control policies must be updated for both the hub and spoke to allow the VPN traffic to and from the tunnel.
-
NGFW1—Access control policy for the hub node (NGFW1)
-
Branch Access Control —Access control policy for the spoke node (NGFWBR1)
Procedure
| 1. | To edit the hub node (NGFW1) AC policy, click the Edit ( The existing rules that must be modified for this use case are:
|
|
| 2. | To edit the spoke node (NGFWBR1) AC policy, click the Edit ( The rules that must be edited for this example are:
|
