cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Bookmark
|
Subscribe
|
2717
Views
0
Helpful
6
Replies

Firepower 2130 support site to site vpn to google cloud with bgp routing option

Daniel8
Level 1
Level 1

Does Firepower 2130 support site to site vpn  to Goggle cloud with bgp routing option?? if so, how to do it?? Thanks.

6 Replies 6

Marvin Rhoads
Hall of Fame
Hall of Fame

Site-site IPsec VPN to third party peers (other vendor devices or public cloud) is supported. It's no different from any other site-site VPN. You just choose "extranet" for the remote peer to indicate it will be setup separately from the FMC-managed device.

 

BGP is independent of that but is also supported.

 

I have setup site-site VPNs to unmanaged remote devices and the FTD is using BGP for its external routing. It works fine.

Hi Marvin!

 

Do you have any example of configuration on the cisco firepower 2130 side for the vpn site to site with Google cloud?

From already thank you very much!

Greetings,

Site-to-site setups are fairly guided. Things that you will need to consider include the use of IKEv1 (deprecated) or IKEv2, cipher suite (encryption, Diffie-Helman group, integrity, PFS, etc)

As IPsec is standardized here are some recommended settings to meet best practice

Encryption: AES-256

Integrity: SHA512

DH-Group: (minimum 14- but higher is better)

IKEv2 over IKEv1

PFS is preferred. 

The Firepower guide can be found here: Site to Site VPN Configuration on FTD Managed by FMC - Cisco

And the Google guide can be found here: Use third-party VPNs  |  Google Cloud

Hope this helps.

Please mark as helpful if this answered your question!

How did you achieve this, route based or policy-based?

Routing protocol function well with route based.

Review Cisco Networking for a $25 gift card