11-05-2024 01:58 PM
We are moving our primary internet to a new location and will have a new public IP and gateway. Is there a way to assign the new IP to the outside interface of the FTD, and somehow keep all of our Site to Site VPN tunnels using the existing IP (yes, we will still own it). We are trying to avoid reaching out to each vender to have them swap that IP on their side.
11-06-2024 12:31 AM
@tbduff001 a VPN must be terminated on the IP address assigned to the physical interface (outside). So you'd either need to get your ISP to move the current network or re-terminate your VPN's on the new IP address.
11-07-2024 06:57 AM
FTD still doesn't support multiple IP addresses on its interfaces, so I think the best option you would have would be to schedule this maintenance window and work with the suppliers to update the tunnels IP. Alternatively, you can keep everything as is and ask your ISP to route the new public range to your FTD IP, and then you can use the new public IP range by creating the NAT rules to the devices behind the firewall.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide