<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FTD 2130 - drops all VTIs tunnel to different remote sites. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-2130-drops-all-vtis-tunnel-to-different-remote-sites/m-p/5015607#M1108960</link>
    <description>&lt;P&gt;To say something we at least need topology diagram, configuration fragment with BGP and tunnel interfaces in place (replace all public IPs there with something like 192.0.2.x or x.1.2.3) and syslog from the time of the flap to understand whether BGP flaps on its own or IPSec tunnel flap brings down BGP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2024 16:10:19 GMT</pubDate>
    <dc:creator>tvotna</dc:creator>
    <dc:date>2024-02-09T16:10:19Z</dc:date>
    <item>
      <title>Cisco FTD 2130 - drops all VTIs tunnel to different remote sites.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-2130-drops-all-vtis-tunnel-to-different-remote-sites/m-p/5015193#M1108946</link>
      <description>&lt;P&gt;Hi guys, I have this issue for a long time now. We have two pair of FTDs in HA in two different DCs. We have VTIs setup in both HA pairs going to each remote site. This case have been with Cisco TAC for a long time and we still not get to the real problem. What could cause all BGP neightbors to reset at the same time. I'm thinking a hardware problem or BGP table just flaps randomly. I'm happy to share any outputs or config. Also two of the VTIs are going to Azure.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 21:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-2130-drops-all-vtis-tunnel-to-different-remote-sites/m-p/5015193#M1108946</guid>
      <dc:creator>alonso2352</dc:creator>
      <dc:date>2024-02-08T21:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD 2130 - drops all VTIs tunnel to different remote sites.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-2130-drops-all-vtis-tunnel-to-different-remote-sites/m-p/5015607#M1108960</link>
      <description>&lt;P&gt;To say something we at least need topology diagram, configuration fragment with BGP and tunnel interfaces in place (replace all public IPs there with something like 192.0.2.x or x.1.2.3) and syslog from the time of the flap to understand whether BGP flaps on its own or IPSec tunnel flap brings down BGP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 16:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-2130-drops-all-vtis-tunnel-to-different-remote-sites/m-p/5015607#M1108960</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-02-09T16:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD 2130 - drops all VTIs tunnel to different remote sites.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-2130-drops-all-vtis-tunnel-to-different-remote-sites/m-p/5015989#M1108977</link>
      <description>&lt;P&gt;We would need more information on how your VTI and BGP is setup, and preferably provide the configuration for review.&lt;/P&gt;
&lt;P&gt;The times when I have seen similar issues is when BGP is advertising the public interface IP to the remote side over the VTI tunnel.&amp;nbsp; So, be sure that you are filtering out the public IP from being advertised via BGP.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Feb 2024 23:37:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-2130-drops-all-vtis-tunnel-to-different-remote-sites/m-p/5015989#M1108977</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-02-10T23:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD 2130 - drops all VTIs tunnel to different remote sites.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-2130-drops-all-vtis-tunnel-to-different-remote-sites/m-p/5016077#M1108982</link>
      <description>&lt;P&gt;The VTI tunnel is down when and only when the tunnel source is down and/or tunnel destination is not reachable.&lt;/P&gt;
&lt;P&gt;Your case maybe related to routing issue' that the tunnel destination reachable via tunnel itself (via bgp)&lt;/P&gt;
&lt;P&gt;So check prefix learn from bgp and tunnel destination' there is overlapping in supernet ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 11 Feb 2024 10:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-2130-drops-all-vtis-tunnel-to-different-remote-sites/m-p/5016077#M1108982</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-02-11T10:44:56Z</dc:date>
    </item>
  </channel>
</rss>

