Guest

Preview Tool

Cisco Bug: CSCvs40884 - DOC: Reverse Route Injection enabled by default during S2S configuration in FMC

Last Modified

Apr 14, 2020

Products (1)

  • Cisco Firepower Management Center

Known Affected Releases

6.2.3 6.3.0 6.4.0

Description (partial)

Symptom:
Firepower Management Center Configuration Guide for versions 6.2.3+ should reflect a change in wording for the chapter 'Site-to-Site VPNs for Firepower Threat Defense'.

Curent:

Subnet/IP Address (Network) remains the default selection.

When you have selected Protected Networks as Any and observe default route traffic being dropped, disable the Reverse Route Injection under VPN> Site to Site > edit a VPN > IPsec > Enable Reverse Route Injection. Deploy the configuration changes; this will remove set reverse-route (Reverse Route Injection) from the crypto map configuration and remove the VPN-advertised reverse route that causes the reverse tunnel traffic to be dropped.

Correction:

Reverse Route Injection is enabled (bold) by default when configuring in the Firepower Management Center.

Subnet/IP Address (Network) remains the default selection.

When you have selected Protected Networks as Any and observe default route traffic being dropped, disable the Reverse Route Injection under VPN> Site to Site > edit a VPN > IPsec > Enable Reverse Route Injection. Deploy the configuration changes; this will remove set reverse-route (Reverse Route Injection) from the crypto map configuration and remove the VPN-advertised reverse route that causes the reverse tunnel traffic to be dropped.

Conditions:
Documentation
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.