<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN issue between Cisco FTD and SRX 550 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898920#M31290</link>
    <description>&lt;P&gt;Couple of questions :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. you have both the sides for now working Juniper SRX VPN ?&lt;/P&gt;
&lt;P&gt;2. you wish you upgrade one of site from Juniper SRX&amp;nbsp; to FTD. ( other side remains same as Juniper SRX )&lt;/P&gt;
&lt;P&gt;3. FMC can not see Juniper SRX device, since FMC for cisco device only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is the example config of ASA to SRX ( same should be work with FTD.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB28120&amp;amp;actp=METADATA" target="_blank" rel="noopener"&gt;https://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB28120&amp;amp;actp=METADATA&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can only test as below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. You connnect the new FTD where SRX&amp;nbsp; connected. (but in shutdown mode) - other than Management IP.&lt;/P&gt;
&lt;P&gt;2. When you have maintenance window, shutdown SRX interface and bring up the FTD interface if you like to use same IP and same Setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other Option :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can build with new IP on FTD&amp;nbsp; and New Tunnel to Juniper SRX with far end. ( so you have both the tunnel running same time).&lt;/P&gt;
&lt;P&gt;shift the load once VPN working and testing. if not move the traffic back to Old VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sense ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jul 2019 19:12:41 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2019-07-28T19:12:41Z</dc:date>
    <item>
      <title>VPN issue between Cisco FTD and SRX 550</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898889#M31289</link>
      <description>&lt;P&gt;I have 2 locations with Juniper SRX 550 and needed to migrate these Juniper firewall to Cisco FTDs on HA managed by FMC. All the required configurations have been completed on the FMC. But I need to test the VPN connections between the newly configured Cisco FTDs and the old Juniper SRX.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I launched the VPN setup for P2P on the cisco FMC, it can only see the Cisco HA. how do I make Juniper SRX endpoints connected to the Cisco FMC? Just for testing purpose before I swap out the Juniper.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to setup VPN connection from Cisco FTD HA to the Juniper SRX, and test the connections?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2019 15:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898889#M31289</guid>
      <dc:creator>shinerner</dc:creator>
      <dc:date>2019-07-28T15:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue between Cisco FTD and SRX 550</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898920#M31290</link>
      <description>&lt;P&gt;Couple of questions :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. you have both the sides for now working Juniper SRX VPN ?&lt;/P&gt;
&lt;P&gt;2. you wish you upgrade one of site from Juniper SRX&amp;nbsp; to FTD. ( other side remains same as Juniper SRX )&lt;/P&gt;
&lt;P&gt;3. FMC can not see Juniper SRX device, since FMC for cisco device only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is the example config of ASA to SRX ( same should be work with FTD.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB28120&amp;amp;actp=METADATA" target="_blank" rel="noopener"&gt;https://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB28120&amp;amp;actp=METADATA&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can only test as below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. You connnect the new FTD where SRX&amp;nbsp; connected. (but in shutdown mode) - other than Management IP.&lt;/P&gt;
&lt;P&gt;2. When you have maintenance window, shutdown SRX interface and bring up the FTD interface if you like to use same IP and same Setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other Option :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can build with new IP on FTD&amp;nbsp; and New Tunnel to Juniper SRX with far end. ( so you have both the tunnel running same time).&lt;/P&gt;
&lt;P&gt;shift the load once VPN working and testing. if not move the traffic back to Old VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sense ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2019 19:12:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898920#M31290</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-07-28T19:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue between Cisco FTD and SRX 550</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898925#M31292</link>
      <description>&lt;P&gt;Thanks Balaji for your response, greatly helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Couple of questions :&lt;/P&gt;&lt;P&gt;1. you have both the sides for now working Juniper SRX VPN ? &lt;STRONG&gt;Yes, both sides are working.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2. you wish you upgrade one of site from Juniper SRX&amp;nbsp; to FTD. ( other side remains same as Juniper SRX ). &lt;STRONG&gt;Correct, just one SITE was upgraded to Cisco FTD for a test.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;3. FMC can not see Juniper SRX device, since FMC for cisco device only. &lt;STRONG&gt;That's the main problem.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the example config of ASA to SRX ( same should be work with FTD.)&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB28120&amp;amp;actp=METADATA" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;https://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB28120&amp;amp;actp=METADATA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This link is for Cisco ASA, not for Cisco FTD managed by FMC,&amp;nbsp; but the issue are: -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;How to configure the Cisco FTD thru FMC for site-to-site VPN between the SRX and FMC.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2. When Adding Endpoints in the VPN Configuration on the FMC, for Node A(Cisco FTD), Its easy to add the node from the "Device" drop down option, but for Node B(SRX), unable&amp;nbsp;to add the node.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I will follow your TESTING approach, thanks. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you need more clarification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2019 19:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898925#M31292</guid>
      <dc:creator>shinerner</dc:creator>
      <dc:date>2019-07-28T19:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue between Cisco FTD and SRX 550</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898927#M31294</link>
      <description>&lt;P&gt;As per the orginal post you have mentioned, all the configuration in place.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. When Adding Endpoints in the VPN Configuration on the FMC, for Node A(Cisco FTD), Its easy to add the node from the "Device" drop down option, but for Node B(SRX), unable&amp;nbsp;to add the node.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#0000FF"&gt;Node B you need to create with SRX&amp;nbsp; IP,&amp;nbsp; follow below video :&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=2ivWnEQfdzU" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=2ivWnEQfdzU&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2019 19:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898927#M31294</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-07-28T19:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue between Cisco FTD and SRX 550</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898928#M31296</link>
      <description>&lt;P&gt;Thanks Balaji, that link was so helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;I also got this below link: Create site-to-site with Cisco firepower and 3rd party firewall&lt;/P&gt;&lt;DIV class="style-scope ytd-app"&gt;&lt;DIV class="style-scope ytd-watch-flexy"&gt;&lt;DIV class="style-scope ytd-watch-flexy"&gt;&lt;DIV class="style-scope ytd-watch-flexy"&gt;&lt;DIV class="style-scope ytd-watch-flexy"&gt;&lt;DIV class="style-scope ytd-watch-flexy"&gt;&lt;DIV class="style-scope ytd-video-primary-info-renderer"&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=3F5u_AGp7Us" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=3F5u_AGp7Us&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 28 Jul 2019 20:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898928#M31296</guid>
      <dc:creator>shinerner</dc:creator>
      <dc:date>2019-07-28T20:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue between Cisco FTD and SRX 550</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898944#M31298</link>
      <description>&lt;P&gt;Glad it was helpfull and you able to resolve the issue soon, keep us posted.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2019 22:31:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issue-between-cisco-ftd-and-srx-550/m-p/3898944#M31298</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-07-28T22:31:11Z</dc:date>
    </item>
  </channel>
</rss>

