<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover Site-to-Site IPSec Tunnels Between Two FTDs Managed by FM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover-site-to-site-ipsec-tunnels-between-two-ftds-managed-by/m-p/4763379#M1097242</link>
    <description>&lt;P&gt;if you can config IPsec keepalive,&amp;nbsp;&lt;BR /&gt;we must inform other FW that this tunnel is down and we will establish other tunnel.&amp;nbsp;&lt;BR /&gt;that it&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jan 2023 18:45:05 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-01-26T18:45:05Z</dc:date>
    <item>
      <title>Failover Site-to-Site IPSec Tunnels Between Two FTDs Managed by FMC</title>
      <link>https://community.cisco.com/t5/network-security/failover-site-to-site-ipsec-tunnels-between-two-ftds-managed-by/m-p/4763376#M1097241</link>
      <description>&lt;P&gt;I have two FTDs, one with one ISP and one with two ISPs, and need to have failover tunnels between them. The internet connection fails over with SLA monitor and different metrics. The site-to-site tunnels are set up as route based with two static VTIs on the single ISP connection FTD and one VTI per ISP connection on the one with two ISPs. The tunnel works fine when on primary connection for FTD with two ISPs. The tunnel to the secondary ISP interface never forms, not before or after failover. I have set a timeout on the floating connections in Platform Setting policy to 30 seconds and this didn't change anything. Has anyone made this work? I have attached a diagram for clarity.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 18:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-site-to-site-ipsec-tunnels-between-two-ftds-managed-by/m-p/4763376#M1097241</guid>
      <dc:creator>edh@oneonta.com</dc:creator>
      <dc:date>2023-01-26T18:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Site-to-Site IPSec Tunnels Between Two FTDs Managed by FM</title>
      <link>https://community.cisco.com/t5/network-security/failover-site-to-site-ipsec-tunnels-between-two-ftds-managed-by/m-p/4763379#M1097242</link>
      <description>&lt;P&gt;if you can config IPsec keepalive,&amp;nbsp;&lt;BR /&gt;we must inform other FW that this tunnel is down and we will establish other tunnel.&amp;nbsp;&lt;BR /&gt;that it&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 18:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-site-to-site-ipsec-tunnels-between-two-ftds-managed-by/m-p/4763379#M1097242</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-26T18:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Site-to-Site IPSec Tunnels Between Two FTDs Managed by FM</title>
      <link>https://community.cisco.com/t5/network-security/failover-site-to-site-ipsec-tunnels-between-two-ftds-managed-by/m-p/4763387#M1097246</link>
      <description>&lt;P&gt;Turns out for this configuration to work I needed to set the secondary VTIs as "backup VTIs" in the VPN configuration. I had them set up as two separate tunnels, which for some reason didn't work. Thanks for the reply though!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 19:00:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-site-to-site-ipsec-tunnels-between-two-ftds-managed-by/m-p/4763387#M1097246</guid>
      <dc:creator>edh@oneonta.com</dc:creator>
      <dc:date>2023-01-26T19:00:16Z</dc:date>
    </item>
  </channel>
</rss>

