12-05-2022 12:21 PM
Hello,
I've been reading through Cisco's site to site documentation and wanted to confirm there's no possible way for a site to site vpn to have both tunnels active? Seems you can only have active/passive.
FMC 7.0 using FTD 2100 series.
Thanks in advance
Solved! Go to Solution.
12-06-2022 04:59 AM
It isn't clear if you are asking about S2S VPN with an HA pair of FTD appliances or a single FTD appliance with a primary and backup S2S VPN peer.
Either way, the answer is "no".
12-05-2022 12:27 PM
you mean initiate/responder ??
12-06-2022 04:59 AM
It isn't clear if you are asking about S2S VPN with an HA pair of FTD appliances or a single FTD appliance with a primary and backup S2S VPN peer.
Either way, the answer is "no".
12-06-2022 06:40 AM
@Marvin Rhoads, are traffic zones still not supported on SVTI tunnels in case of FTD? On ASA it is certainly possible to configure them and achieve ECMP over tunnel interfaces or use them in a primary/backup manner.
What is not clear though, is how existing connections are reclassified if one of tunnel interfaces goes down in such scenario.
12-06-2022 07:33 AM
@tvotna seems like they are now supported from 7.1 and higher. - https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/730/management-center-device-config-73/routing-ecmp.html
12-06-2022 07:38 AM
Yes - I believe the recently-introduced route-based (VTI) S2S VPNs along with ECMP are supported. Policy-based (crypto map) does not support it.
I have not tried it myself yet though.
12-06-2022 09:52 AM
Hi Marvin,
Currently, we only have the one FTD in place but soon will have a second FTD setup in HA. I will read up on VTIs and see if those will work in our scenario. Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide