cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

1635
Views
15
Helpful
9
Replies
Hkuespert
Beginner

API VPN Configurations

Are there any plans to allow VPN tunnel creation through the API?  I can't find anything on this subject but have a bulk of VPNs to migrate from ASA.  They weren't brought over using the FTD migration tool.

 

 

9 REPLIES 9
michoudi
Beginner

I was looking for this feature too. So far, I haven't seen any mention if or when it might appear. I ended up spending many, many hours manually inputing L2L configurations.
Marvin Rhoads
VIP Community Legend

FTD and FMC 6.2.3 added several API POST features but unfortunately not the ones needed for site-site VPN configuration.

 

We expect release 6.3 (~Fall 2018) will have a lot more API-based configuration options, including site-site VPN.

It has been a while since he last post. Any updates if L2L VPN functionality was added to the API in version 6.3?

Hi,

Yes, as per the 6.3 release notes

 

The FMC REST API supports new objects for site-to-site VPN topology and HA device failover.

New objects for site-to-site VPN topology: ftds2svpns, endpoints, ipsecsettings, advancedsettings, ikesettings, ikev1ipsecproposals, ikev1policies, ikev2ipsecproposals, ikev2policies

 

HTH

Great! Thanks for the quick reply

Are there any examples/resources out there for importing s2s VPNs? Everything I'm finding is related to objects, which are relatively simple to do.

Can someone give us an example of how to do the script because the example in the API Spec do just give "string" as an example so maybe you could supply us with something more useful.. just a thought :-).

Marvin Rhoads
VIP Community Legend

The Firepower Migration Tool v2 (due out in the next month or so) will include VPN migration.

Great, thank you :-) because I have an ASA with about 350 L2L tunnels and if I have to configure them via the GUI it'll take me many many many hours. For that reason, I haven't migrated to FTD yet.