Firepower 2130 support site to site vpn to google cloud with bgp routing option
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-05-2019 11:47 AM - edited 03-12-2019 07:16 AM
Does Firepower 2130 support site to site vpn to Goggle cloud with bgp routing option?? if so, how to do it?? Thanks.
- Labels:
-
NGIPS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-05-2019 07:31 PM
Site-site IPsec VPN to third party peers (other vendor devices or public cloud) is supported. It's no different from any other site-site VPN. You just choose "extranet" for the remote peer to indicate it will be setup separately from the FMC-managed device.
BGP is independent of that but is also supported.
I have setup site-site VPNs to unmanaged remote devices and the FTD is using BGP for its external routing. It works fine.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-07-2021 02:00 PM
Hi Marvin!
Do you have any example of configuration on the cisco firepower 2130 side for the vpn site to site with Google cloud?
From already thank you very much!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-07-2021 02:26 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-07-2024 10:32 PM
Greetings,
Site-to-site setups are fairly guided. Things that you will need to consider include the use of IKEv1 (deprecated) or IKEv2, cipher suite (encryption, Diffie-Helman group, integrity, PFS, etc)
As IPsec is standardized here are some recommended settings to meet best practice
Encryption: AES-256
Integrity: SHA512
DH-Group: (minimum 14- but higher is better)
IKEv2 over IKEv1
PFS is preferred.
The Firepower guide can be found here: Site to Site VPN Configuration on FTD Managed by FMC - Cisco
And the Google guide can be found here: Use third-party VPNs | Google Cloud
Hope this helps.
Please mark as helpful if this answered your question!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-16-2024 07:30 AM
How did you achieve this, route based or policy-based?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-07-2024 12:10 PM
Routing protocol function well with route based.
