Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Configure the Access Control Policy

Updated: February 5, 2026

Overview

Provides instructions for configuring access control policies to allow traffic across a route-based site-to-site VPN using Firewall Management Center (FMC).

Before proceeding, ensure that the VTI interfaces on NGFW1 and NGFWBR1 nodes are associated to a new zone labeled as Tunnel_Zone.

Navigate to Policies > Access Control to review the access control policies. The following access control policies must be updated for both the hub and spoke to allow the VPN traffic to and from the tunnel.

  • NGFW1—Access control policy for the hub node (NGFW1)

  • Branch Access Control —Access control policy for the spoke node (NGFWBR1)

Procedure

1.

To edit the hub node (NGFW1) AC policy, click the Edit (edit icon) icon.

The existing rules that must be modified for this use case are:

  • Allow-To-Branch-Over-Tunnel

  • Allow-To-Corp-Over-Tunnel

  1. To edit the Allow-To-Branch-Over-Tunnel policy, click the Edit (edit icon) icon.

  2. In the Zones tab, search for Tunnel_Zone, select it, and click Add Destination Zone.

    Screenshot of AC policy destination zone configuration for a hub device
  3. Click Apply to save the rule.

  4. To edit the Allow-To-Corp-Over-Tunnel policy, click the Edit (edit icon) icon.

  5. In the Zones tab, search for Tunnel_Zone, select it, and click Add Source Zone.

    Screenshot of AC policy source zone configuration for a hub device
  6. Click Apply to save the rule.

  7. Verify the updated rules in NGFW1.

  8. Click Save the AC policy.

  9. Click Return to Access Conrol Policy Management to return the policy page.

2.

To edit the spoke node (NGFWBR1) AC policy, click the Edit (edit icon) icon.

The rules that must be edited for this example are:

  • Allow-To-Branch-Over-Tunnel

  • Allow-To-Corp-Over-Tunnel

  1. To edit the Allow-To-Branch-Over-Tunnel policy, click the Edit (edit icon) icon.

  2. In the Zones tab, search for Tunnel_Zone, select it, and click Add Souce Zone.

    Screenshot of AC policy source zone configuration for a spoke device
  3. Click Apply to save the rule.

  4. To edit the Allow-To-Corp-Over-Tunnel policy, click the Edit (edit icon) icon.

  5. In the Zones tab, search for Tunnel_Zone, select it, and click Add Destination Zone.

    Screenshot of AC policy destination zone configuration for a spoke device
  6. Click Apply to save the rule.

  7. Verify the updated rules in NGFWBR1.

  8. Click Save the AC policy.