03-14-2018 12:54 PM - edited 02-21-2020 07:30 AM
Hi,
I am familiar with ASA but not with FTD. I have setup a policy-based (IKEv1) tunnel with Azure but now I want to set up a Route-Based tunnel with Azure.
By mistake or luck, I ordered an ASA-5506-FTD-K9 firewall. I wondered if somebody has managed to create a S2S tunnel between this device and Azure.
Now, regular tunnels are policy based and easy to configure. Route based, require a custom config on the Azure side. It requires to enable Traffic Selectors:
Set-AzureRmVirtualNetworkGatewayConnection -VirtualNetworkGatewayConnection $connection6 -UsePolicyBasedTrafficSelectors $True
I am using the ASA configuration as guidance from the URL:
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-3rdparty-device-config-cisco-asa
But I am wondering if you have managed to make this work for your company. Any help could be appreciated.
Thanks,
Solved! Go to Solution.
03-14-2018 09:10 PM
03-14-2018 09:10 PM
03-16-2018 09:48 AM
Thank you Francesco. I opened a TAC Case and the Engineer told me the trick is in the Azure part. If I set the TrafficSelectors option I could use policy-based configurations with a route-based gateway.
I will do a couple of test and I will update this discussion with my results.
Thanks for replying.
R
03-17-2018 09:06 PM
05-11-2018 11:49 AM
Just wanted to provide an update.
Similar to Francesco, I created a IKEv1 tunnel to one of my branch offices but not directly to Azure. I think it will be possible. I don't see why not. The only caveats is that you need to customize your local gateway in Azure with powershell scripts.
To customize the local gateway, you need to use the UsePolicyBasedTrafficSelectors $True.
FMC was out of the question for me because the Firewall is located in the branch office, and it's not a good idea to manage your Firewall using the outside interface.
I find this FTD firewalls lacking of several features. I hit a bug and couldn't even manage the Firewall using the inside interface via the VPN Tunnel.
But yes, it is possible to create an IKEv2 Tunnel to Azure using the FTD and customizing the Azure gateway via powershell.
Thanks,
RG
05-11-2018 01:31 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide