11-25-2020 02:12 AM
11-25-2020 06:07 AM - edited 11-25-2020 06:18 AM
I assume you are referring to having an FTD at the central location, with 2 internet connections (Primary/Secondary)?
I've not see any documentation for a full mesh with backup interfaces scenario. I've tested on FTD 6.5, the problem is when defining a VPN topology you can only specify 1 interface, not both. In this scenario, cisco would usually recommend a router at the hub.
You cannot create 1 Mesh Topology, but you can get creative and define multiple VPN topologies to achieve the same thing.
1 x Hub/Spoke topology - HQ-FTD (Primary ISP interface) > Extranet (spoke ip)
1 x Hub/Spoke topology - HQ-FTD (Secondary ISP interface) > Extranet (spoke ip)
1 x Hub/Spoke topology - Spoke (the FMC managed object) > Extranet Hub (define multiple peer IP address)
1 x Mesh topology for all spokes
Use IP SLA on the hub to failover to the secondary ISP if the primary fails. Use DPD on the spokes to detect the Primary ISP failure.
HTH
11-25-2020 03:48 AM
Look at the below guide may help you:
11-25-2020 06:07 AM - edited 11-25-2020 06:18 AM
I assume you are referring to having an FTD at the central location, with 2 internet connections (Primary/Secondary)?
I've not see any documentation for a full mesh with backup interfaces scenario. I've tested on FTD 6.5, the problem is when defining a VPN topology you can only specify 1 interface, not both. In this scenario, cisco would usually recommend a router at the hub.
You cannot create 1 Mesh Topology, but you can get creative and define multiple VPN topologies to achieve the same thing.
1 x Hub/Spoke topology - HQ-FTD (Primary ISP interface) > Extranet (spoke ip)
1 x Hub/Spoke topology - HQ-FTD (Secondary ISP interface) > Extranet (spoke ip)
1 x Hub/Spoke topology - Spoke (the FMC managed object) > Extranet Hub (define multiple peer IP address)
1 x Mesh topology for all spokes
Use IP SLA on the hub to failover to the secondary ISP if the primary fails. Use DPD on the spokes to detect the Primary ISP failure.
HTH
11-25-2020 06:20 AM
Thank you all for your quick response ,
Belaji i red this link .
Rob i am testing these scenarios ,
we have a full mesh vpn topology with 10 ftd's all in HA , in our central location the internet connection is stable the problem is in the remote sites if the primary internet connection fails the backup is a vdsl line .
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide