cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
202
Views
1
Helpful
2
Replies

Moving FTD to new Public IP, Site to Site VPN question

tbduff001
Level 1
Level 1

We are moving our primary internet to a new location and will have a new public IP and gateway. Is there a way to assign the new IP to the outside interface of the FTD, and somehow keep all of our Site to Site VPN tunnels using the existing IP (yes, we will still own it). We are trying to avoid reaching out to each vender to have them swap that IP on their side. 

2 Replies 2

@tbduff001 a VPN must be terminated on the IP address assigned to the physical interface (outside). So you'd either need to get your ISP to move the current network or re-terminate your VPN's on the new IP address.

FTD still doesn't support multiple IP addresses on its interfaces, so I think the best option you would have would be to schedule this maintenance window and work with the suppliers to update the tunnels IP. Alternatively, you can keep everything as is and ask your ISP to route the new public range to your FTD IP, and then you can use the new public IP range by creating the NAT rules to the devices behind the firewall.

Review Cisco Networking for a $25 gift card