10-03-2023 03:30 AM
Hi
We have an FTD with Global and 3 Virtual Routers(vrf) configured on it all these use the same default route via Global Inet connection,
Is it possible for me to esatablish a VPN from the Inet facing Interface and allow only one VRF's traffic across the VPN, So basically this VRF would now send all its traffic via the VPN.??
Thanks
Solved! Go to Solution.
10-03-2023 05:14 AM
@benolyndav so if the VPN is in the global routing table, then routing leaking from a user-defined vrf should work.
I assumed you wanted to use user-defined VRF for VPNs, which is not supported unless using a VTI (on newer FTD versions).
10-03-2023 03:44 AM
@benolyndav what version of FTD are you using? Are you using a Policy or Route Based VPN (VTI)?
The latest version 7.3/7.4 supports user-defined virtual routers (VRFs) for VTIs
10-03-2023 04:31 AM
Hi
We are using Policy Based VPN
Thanks
10-03-2023 04:35 AM
@benolyndav unfortunately I do not believe virtual routers (VRF) are supported using policy based VPNs, only routed based VPN (VTI) appear to support VRF.
10-03-2023 04:48 AM
Hi
So the vpn is between the outside interface and the 3rd party peer the outside interface is in the gloal routing I would add the traffic to the vpn and add a static route in the vrf any-ipv4 to internet which is leaked from global, are you saying that wouldnt work ??
Thanks
10-03-2023 05:14 AM
@benolyndav so if the VPN is in the global routing table, then routing leaking from a user-defined vrf should work.
I assumed you wanted to use user-defined VRF for VPNs, which is not supported unless using a VTI (on newer FTD versions).
10-03-2023 06:26 AM
Friend it work use pbr and forward traffic via vpn.
Did you check this solution?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide