02-05-2019 11:47 AM - edited 03-12-2019 07:16 AM
Does Firepower 2130 support site to site vpn to Goggle cloud with bgp routing option?? if so, how to do it?? Thanks.
02-05-2019 07:31 PM
Site-site IPsec VPN to third party peers (other vendor devices or public cloud) is supported. It's no different from any other site-site VPN. You just choose "extranet" for the remote peer to indicate it will be setup separately from the FMC-managed device.
BGP is independent of that but is also supported.
I have setup site-site VPNs to unmanaged remote devices and the FTD is using BGP for its external routing. It works fine.
12-07-2021 02:00 PM
Hi Marvin!
Do you have any example of configuration on the cisco firepower 2130 side for the vpn site to site with Google cloud?
From already thank you very much!
12-07-2021 02:26 PM
12-07-2024 10:32 PM
Greetings,
Site-to-site setups are fairly guided. Things that you will need to consider include the use of IKEv1 (deprecated) or IKEv2, cipher suite (encryption, Diffie-Helman group, integrity, PFS, etc)
As IPsec is standardized here are some recommended settings to meet best practice
Encryption: AES-256
Integrity: SHA512
DH-Group: (minimum 14- but higher is better)
IKEv2 over IKEv1
PFS is preferred.
The Firepower guide can be found here: Site to Site VPN Configuration on FTD Managed by FMC - Cisco
And the Google guide can be found here: Use third-party VPNs | Google Cloud
Hope this helps.
Please mark as helpful if this answered your question!
10-16-2024 07:30 AM
How did you achieve this, route based or policy-based?
12-07-2024 12:10 PM
Routing protocol function well with route based.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide