cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3125
Views
0
Helpful
1
Replies

FTDv Integration with AWS Transit Gateway

Hi Team,

I'm looking for a Cisco recommended design for deploying & integrating FTDv FW pair with AWS Transit Gateway.

 

Design Considerations -

  • The 2 firewalls need to be deployed in a separate AWS VPC with 2 availability zones. And traffic failover should be automatic in case of a FTDv or an Availability Zone failure.

 

I could find only the following design ( briefly described in https://www.youtube.com/watch?v=Utthj_CGfP8 ) under Cisco Secure Firewall YouTube channel. And in this design, 2 CSR 1000V routers are used in addition to the 2FTDv FWs. 

I'm not sure why the 2 CSR 1000V routers are required here ?

 

 

 

Cisco-Solution.png

1 Reply 1

vgaur
Level 1
Level 1

Since FTD unfortunately don't support GRE termination for some reason even though Cisco invented GRE, there's no direct way to connect the FTD with Transit Gateway.

I want to utilize BGP to share routing updates with Transit Gateway's routing table but stuck due to this limitation and I don't know if this is in the roadmap to allow GRE termination on FTD.

Review Cisco Networking for a $25 gift card