cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
780
Views
1
Helpful
18
Replies

BGP between two remote FTD

I have two Firepowers in two remote offices and i have two ISPs in each office, i had configured vti ipsec vpn between two offices but they are working with static routes, can i configure dynamic routing protocols for failover vpn? I tried to configure BGP but neighbours idle, what can you advice?

18 Replies 18

Have you changed from using the WAN interface IP to the VTI IP in the BGP neighbor command?

You would also need to preempt BGP AS on the backup VTI on both sides so that only one link (Primary link) is used.  if the primary link fails this configuration will now automatically failover to the secondary VTI.

--
Please remember to select a correct answer and rate helpful posts

@sherali mamatkarimov have you configured Send Virtual Tunnel Interface IP to the peers and Allow incoming IKEv2 routes from the peers under the VPN endpoint?

I haven't this option

 111.png

Marvin Rhoads
Hall of Fame
Hall of Fame

What are your software versions at both ends?

Review Cisco Networking products for a $25 gift card