04-27-2022 12:52 PM
My current 5516-X pair is acting as internet border, AnyConnect VPN headend, and IPSec VPN concentrator. Looking at converting to an FPR-1100 pair. If these are the only FW pair using FTD software, do I need the FMC software? Also, are there any guides out there for converting all of these functions from ASA to FTD code?
04-27-2022 01:01 PM - edited 04-27-2022 01:23 PM
@RANT If using the FMC to manage the FTD you do get more supported features compared to if managed the FTD locally using FDM. What functionality of the RAVPN do you currently use? Of the top of my head, FDM does not currently support dynamic split tunnelling or a tunnelled default route for VPN traffic.
Here is a re-image guide https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/reimage/asa-ftd-reimage.html.... however you'd have to reconfigure the device from scratch. There is a migration tool if using FMC to manage the FTD, but there is none if using FDM. You can purchase a relatively cheap FMCv license to manage 2 devices.
04-27-2022 01:42 PM
So I'm not doing the dynamic split tunneling at the moment using FQDNs. I'm doing split tunneling using the standard ACL applied to the AnyConnect Connection profile.
04-27-2022 01:47 PM
@RANT fine, standard split tunnelling with FDM is supported.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide