<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD Site to Site VPN Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5339131#M1123185</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; what do you mean exactly? what did you envisage the ACL is used for?&lt;/P&gt;</description>
    <pubDate>Thu, 16 Oct 2025 13:12:38 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2025-10-16T13:12:38Z</dc:date>
    <item>
      <title>FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330452#M1122723</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Quick question, Is it possible to Configure a RB VPN on an FTD using a Loopback Interface.??&lt;/P&gt;&lt;P&gt;I ask because I have been requested to set up one but the thing is the peer IP I have to use my side is not one of the FTD Interface IP Addresses, Also is this the best way to achieve this or is there another way. ??&lt;/P&gt;&lt;P&gt;Thankyou&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 08:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330452#M1122723</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-09-16T08:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330454#M1122724</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;yes you can use a loopback on a route based VPN (VTI or DVTI)&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/770/management-center-device-config-77/vpn-s2s.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/770/management-center-device-config-77/vpn-s2s.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Loopback feature was introduced in version 7.3 -&amp;nbsp;&lt;A href="https://secure.cisco.com/secure-firewall/v7.3/docs/loopback-interface" target="_blank"&gt;https://secure.cisco.com/secure-firewall/v7.3/docs/loopback-interface&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 09:03:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330454#M1122724</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-09-16T09:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330455#M1122725</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/internet-security-association-key-management-protocol-isakmp/222055-configure-route-based-site-to-site-vpn-b.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/internet-security-association-key-management-protocol-isakmp/222055-configure-route-based-site-to-site-vpn-b.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Yes you can&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check above link&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 09:01:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330455#M1122725</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-16T09:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330853#M1122737</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;So excuse my ignorance but when creating a RB VPN its suggested to use the 169.x.x.x IP Addresses I have done these before without any issues,&amp;nbsp; not sure how this works or needs configuring if I am to use a loopback address for the local&amp;nbsp; RB VPN address.??&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 08:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330853#M1122737</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-09-17T08:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330855#M1122738</link>
      <description>&lt;P&gt;Now give any IP to LO (unused IP) like 1.1.1.1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then check vti tunnel source can you select Lo as tunnel source?&lt;/P&gt;
&lt;P&gt;If Yes then it OK what you need is static route for Remote LO toward WAN interface&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If NOT then FMC/FTD not support LO as tunnel source&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 08:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330855#M1122738</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-17T08:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330874#M1122740</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for that and yes I do see the Loopback available for the VTI, So because the IP Address I am using and the 3rd party will be peering with is not an Interface IP Address is this the only way I can do it ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 09:37:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330874#M1122740</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-09-17T09:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330877#M1122741</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;sounds like you need to use the loopback as the tunnel source rather than the interface IP address. You obviously have the correct IP address defined on the loopback.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1758102005004.png" style="width: 574px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252013i35A877DB04FDEBCE/image-dimensions/574x224?v=v2" width="574" height="224" role="button" title="RobIngram_0-1758102005004.png" alt="RobIngram_0-1758102005004.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 09:41:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330877#M1122741</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-09-17T09:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330878#M1122742</link>
      <description>&lt;P&gt;Let summary&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VTI use WAN (public IP) as tunnel source' vti will be UP since public IP is reachable&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Vti using LO&amp;nbsp; (as tunnel srouce) with any IP' if remote peer can not reach this IP vti will be down&lt;/P&gt;
&lt;P&gt;Note:-&amp;nbsp; you can ONLY use LO as tunnel source.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 09:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5330878#M1122742</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-17T09:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335059#M1122995</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Yes I have selected that but what about the below what do I need to select for this please&lt;BR /&gt;P.s sorry about the delayed response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="benolyndav_0-1759315402158.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252842i4F7C39C507E6CE78/image-size/medium?v=v2&amp;amp;px=400" role="button" title="benolyndav_0-1759315402158.png" alt="benolyndav_0-1759315402158.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 10:44:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335059#M1122995</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-10-01T10:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335060#M1122996</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;the loopback interface can be used as either a tunnel source or a borrow source, but not both. So if you want to terminate the VPN on the loopback, select tunnel source only.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 10:54:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335060#M1122996</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-10-01T10:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335072#M1122997</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;So I need to use something from the below range for the VTI IP&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="benolyndav_0-1759317984640.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252843i3C54C122C738C21A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="benolyndav_0-1759317984640.png" alt="benolyndav_0-1759317984640.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 11:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335072#M1122997</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-10-01T11:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335073#M1122998</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;for the VTI tunnel IP address, I would typically&amp;nbsp;personally use an IP address from the internal LAN network space. Personal choice though. It needs to be routed over the tunnel and unique.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 11:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335073#M1122998</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-10-01T11:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335685#M1123027</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;So if I use a 169.254.7.X/30 address for my vti and the loopback for the tunnel source, what do I point my static routes to for traffic going over the tunnel ??&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 13:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335685#M1123027</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-10-03T13:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335690#M1123028</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;You'd point the route to the peer's tunnel IP address in the&amp;nbsp;169.254.7.X/30 network.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 13:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335690#M1123028</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-10-03T13:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335692#M1123029</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;They aren't using one in that range that's the thing .??&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 14:00:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335692#M1123029</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-10-03T14:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335694#M1123030</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;configure both tunnel interfaces (yours and the peers) in the same network, so they can communicate. Then create static routes (or use dynamic) for the local networks.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 14:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5335694#M1123030</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-10-03T14:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5338736#M1123165</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Is it possible to use a NAT address has the peer IP address for RB/PB Site to Site VPNs at all on FTD??&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 09:22:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5338736#M1123165</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-10-15T09:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5338747#M1123167</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;do you mean you want to setup your VPN to peer with an IP address that's actually a NAT on the remote side? If so yes, assuming the NAT is configured correctly on the remote side to translate the NAT IP to the IP address of the firewall/router you wish to establish a tunnel to. You will need to ensure NAT Traversal is configured on both ends to detect that NAT.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 09:28:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5338747#M1123167</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-10-15T09:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5338833#M1123169</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Hi so say I wanted the remote peer end to peer with an NAT IP Address of 192.175.125.23&amp;nbsp; on my side&amp;nbsp;&lt;BR /&gt;how would I need my NAT setting up out and in&amp;nbsp;&lt;BR /&gt;so the remote peer is IP 205.190.190.1&lt;/P&gt;&lt;P&gt;and myside local peer that they need to peer with is NAT IP Address&amp;nbsp;192.175.125.23&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 14:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5338833#M1123169</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2025-10-15T14:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Site to Site VPN Question</title>
      <link>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5338835#M1123170</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt; the tunnel source should be a physical or loopback interface IP, so not I don't think that will work.&amp;nbsp;Can you not assign that NAT IP as a loopback, and use that as the tunnel source?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 14:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-site-to-site-vpn-question/m-p/5338835#M1123170</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-10-15T14:13:00Z</dc:date>
    </item>
  </channel>
</rss>

