<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec migration From ASA to FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3786165#M991701</link>
    <description>ok but how do you exactly do that? Through a wildcard within the P2P topology?</description>
    <pubDate>Wed, 23 Jan 2019 15:28:28 GMT</pubDate>
    <dc:creator>NETAD</dc:creator>
    <dc:date>2019-01-23T15:28:28Z</dc:date>
    <item>
      <title>IPsec migration From ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3784439#M991693</link>
      <description>&lt;P&gt;Hello, I'm migrating 33 IPsec tunnels from a 5520 to a 2110 FTD. I ran into couple issues:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1-Trying to do a hub and spoke topology but there's a limitation with the pre-shared key that it should be the same across all the spokes. Why is that&lt;/P&gt;
&lt;P&gt;2-I have few spokes with dynamic IPs but FMC gives only the option to chose either static or dynamic&lt;/P&gt;
&lt;P&gt;3-If I decided to create 33 point-to-point tunnels, how can I allow spoke to spoke traffic, and how would I configure the dynamic tunnels? In my lab I tried creating a wildcard for the dynamic tunnels but they didn't come up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:40:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3784439#M991693</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2020-02-21T16:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec migration From ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785050#M991694</link>
      <description>&lt;P&gt;If you don't want to or are unable to use the same PSK, you will need to create all of the site-site VPNs separately.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Spoke to spoke traffic will have to flow through the hub and must be allowed by the crypto map(s) and any NAT exemptions will need to take it into account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately the FTD platform doesn't offer anything like DMVPN or such as is available on IOS-based routers.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 13:57:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785050#M991694</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-01-22T13:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec migration From ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785213#M991696</link>
      <description>&lt;P&gt;Thanks Marvin, what about the dynamic tunnels?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 16:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785213#M991696</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2019-01-22T16:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec migration From ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785300#M991697</link>
      <description>Hi,&lt;BR /&gt;Dynamic crypto can be able to configure in FTD.</description>
      <pubDate>Tue, 22 Jan 2019 17:44:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785300#M991697</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2019-01-22T17:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec migration From ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785529#M991698</link>
      <description>&lt;P&gt;Not when you create p2p tunnels.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 21:48:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785529#M991698</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2019-01-22T21:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec migration From ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785716#M991699</link>
      <description>Hi.&lt;BR /&gt;You can configure dynamic cryptomap for L2L tunnels. scenario like the spoke have a dynamic IP and HUB have static IP. But you need to share the same shared secret across all the dynamic spokes. &lt;BR /&gt;As Marvin said you can allow spoke to spoke traffic via HUB. &lt;BR /&gt;&lt;BR /&gt;Hope This Helps&lt;BR /&gt;Abheesh</description>
      <pubDate>Wed, 23 Jan 2019 05:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3785716#M991699</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2019-01-23T05:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec migration From ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3786165#M991701</link>
      <description>ok but how do you exactly do that? Through a wildcard within the P2P topology?</description>
      <pubDate>Wed, 23 Jan 2019 15:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3786165#M991701</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2019-01-23T15:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec migration From ASA to FTD</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3788734#M991703</link>
      <description>&lt;P&gt;We configured all tunnels as S2S and the dynamic ones as hub and spoke with a wild card(0.0.0.0) for remote peers. Spoke to spoke communication is allowed by checking a check box within the hub and spoke topology.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For spoke to spoke communication through the hub between the S2S tunnels, we summarized all the spoke networks and entered it on each spoke S2S in the hub protected networks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In addition we had to configure an access rule from outside to outside to allow the spoke to spoke communication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not to forget the NAT exemptions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help on this.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 22:00:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-migration-from-asa-to-ftd/m-p/3788734#M991703</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2019-01-26T22:00:18Z</dc:date>
    </item>
  </channel>
</rss>

