cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
876
Views
15
Helpful
4
Replies

FTD/FMC VTI Tunnel

Sastic76
Level 1
Level 1

Hi,

 

If we are using an FTD device and building out a IPSEC VTI tunnel to connect to a distant end which is using IPSEC GRE and then route BGP over that, will the FTD be able to establish connection? I know it won't natively do GRE but will the two sides be able to get through phase1/2 and build a tunnel that way?

1 Accepted Solution

Accepted Solutions

NO because there is GRE header add to packet and since both side not use same tunnel, then when other Peer receive this packet with GRE header it will drop it.

View solution in original post

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

NO because there is GRE header add to packet and since both side not use same tunnel, then when other Peer receive this packet with GRE header it will drop it.

So that would be the reason why we are seeing ERROR: Auth exchange failed is because its effectively getting malformed by the GRE header drop?

Yes probably

Review Cisco Networking products for a $25 gift card