cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


553
Views
0
Helpful
5
Replies
Beginner

Configure VTI in Active/Active Scenario

Will I be able to configure VTI on Active/Active ASA pair?

Everyone's tags (1)
5 REPLIES 5
Frequent Contributor

Re: Configure VTI in Active/Active Scenario

Hi,
This is currently supported on single context / routed mode only. With you mentioning active/active I'm assuming you're running multicontext.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/vpn/asa-98-vpn-config/vpn-vti.html
Beginner

Re: Configure VTI in Active/Active Scenario

We were planning to move to Active/Active setup from Active/Standby setup.

But as I read Active/Active is only supported in multiple context mode.

And VTI is supported in only Single context mode.

If this is true I will not be able to configure VTI in Active/Active setup, right?

Frequent Contributor

Re: Configure VTI in Active/Active Scenario

Yes that is correct.

Rising star

Re: Configure VTI in Active/Active Scenario

 

Just make sure you are on 9.7 onward version of the ASA code. As VTI was introduce in 9.7 code here is the link in case you need it in regards to configurations

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/vpn/asa-97-vpn-config/vpn-vti.pdf

please do not forget to rate.
Highlighted
Beginner

Re: Configure VTI in Active/Active Scenario

In addition to this, is it possible to configure two tunnels using different ISPs and keep them active? Please find the attachment for the reference. (Assume ASA1 is active firewall).

In that, I want to keep tunnel to 1.1.1.1 and 3.3.3.3 active.

 

Everyone's tags (1)