cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2545
Views
5
Helpful
6
Replies

Configure VTI in Active/Active Scenario

umeshunited
Level 1
Level 1

Will I be able to configure VTI on Active/Active ASA pair?

6 Replies 6

GRANT3779
Spotlight
Spotlight
Hi,
This is currently supported on single context / routed mode only. With you mentioning active/active I'm assuming you're running multicontext.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-vti.html

We were planning to move to Active/Active setup from Active/Standby setup.

But as I read Active/Active is only supported in multiple context mode.

And VTI is supported in only Single context mode.

If this is true I will not be able to configure VTI in Active/Active setup, right?

Yes that is correct.

 

Just make sure you are on 9.7 onward version of the ASA code. As VTI was introduce in 9.7 code here is the link in case you need it in regards to configurations

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/vpn/asa-97-vpn-config/vpn-vti.pdf

please do not forget to rate.

Are there any workarounds available to accomplish VTI tunnel in multiple contexts? 

Currently running 9.8.4. multiple context HA 5545.

I require it for umbrella setup. 

Thank you.

umeshunited
Level 1
Level 1

In addition to this, is it possible to configure two tunnels using different ISPs and keep them active? Please find the attachment for the reference. (Assume ASA1 is active firewall).

In that, I want to keep tunnel to 1.1.1.1 and 3.3.3.3 active.

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card