cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
635
Views
10
Helpful
6
Replies

FMC Site to Site VPN Question

dcanady55
Level 3
Level 3

Hello,

I've been reading through Cisco's site to site documentation and wanted to confirm there's no possible way for a site to site vpn to have both tunnels active? Seems you can only have active/passive. 

FMC 7.0 using FTD 2100 series. 

Thanks in advance

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

It isn't clear if you are asking about S2S VPN with an HA pair of FTD appliances or a single FTD appliance with a primary and backup S2S VPN peer.

Either way, the answer is "no".

View solution in original post

6 Replies 6

you mean initiate/responder ??

Marvin Rhoads
Hall of Fame
Hall of Fame

It isn't clear if you are asking about S2S VPN with an HA pair of FTD appliances or a single FTD appliance with a primary and backup S2S VPN peer.

Either way, the answer is "no".

@Marvin Rhoads, are traffic zones still not supported on SVTI tunnels in case of FTD? On ASA it is certainly possible to configure them and achieve ECMP over tunnel interfaces or use them in a primary/backup manner.

What is not clear though, is how existing connections are reclassified if one of tunnel interfaces goes down in such scenario.

Yes - I believe the recently-introduced route-based (VTI) S2S VPNs along with ECMP are supported. Policy-based (crypto map) does not support it.

I have not tried it myself yet though.

Hi Marvin,

Currently, we only have the one FTD in place but soon will have a second FTD setup in HA. I will read up on VTIs and see if those will work in our scenario. Thanks

Review Cisco Networking for a $25 gift card