08-20-2020 11:18 AM
I do not think FTD does but figure it is better check here, in case I missed anything...
I have FTD HA running v6.4.0.9 and the pair is managed by FMC. There are two Internet circuits (A and B) for the FTD which I setup IP SLA tracking for Internet failover already. The FTD has already also built a S2S tunnel via Internet A to another location. So does FTD support to have Internet B as backup to built the S2S tunnel to the same remote location if Internet A is down?
I could create a S2S VPN in FMC for the FTD using Internet B interface to this remote location (with necessary NAT and Pre-filter rules). The peer VPN device (ASA) can also be updated with Internet A&B IP addresses as peer...But the tunnel failed to come up at all...
08-20-2020 07:41 PM
If you have created a second tunnel (with associated rules) definition and the routing flips over to that second interface / ISP then the tunnel should come up. I'd recommend digging into that behavior a bit deeper. A TAC case would probably be the most effective approach as it would be best worked with real time troubleshooting.
08-21-2020 05:37 AM
The setup is working now after I rebuilt the backup tunnel profile on FMC...I still donot know where went wrong the first time though.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide