Updating firewall policies
Let’s not forget to add a firewall rule for this traffic! The tunnel interface name is different on each Hub (since it includes the ID of the remote Hub).
We will use per-device mapping when defining our normalized interfaces in FMG:
Normalized Interface |
Per-Device Mapping |
---|---|
OL_INET_DC2DC |
DC1_FGT: OL_INET_12 DC2_FGT: OL_INET_11 |
OL_MPLS_DC2DC |
DC1_FGT: OL_MPLS_22 DC2_FGT: OL_MPLS_21 |
To update firewall policies for hubs:
- Go to Policy & Objects > Policy Packages.
- In the tree menu, select the policy package for hubs, for example, DataCenter-PP. The firewall policies in the policy package are displayed.
- Add policies to the firewall policy:
- In the toolbar, click Create New. The Create New Firewall Policy pane is displayed.
- Create the following policy, and click OK.
Name
From
To
Src
Dst
Service
NAT
Action
DC to DC
vl_lan
OL_INET_DC2DC
OL_MPLS_DC2DC
vl_lan
OL_INET_DC2DC
OL_MPLS_DC2DC
all
all
ALL
No
Accept
- Install the DataCenter-PP policy package to hub devices.