cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
289
Views
0
Helpful
3
Replies

Site2site vpn setup on 2110 FTD

Chuck Reimer
Level 1
Level 1

Is it possible to setup an FTD 2110 cluster that would support VPN and/or Site2Site connections?

1 Accepted Solution

Accepted Solutions

@Chuck Reimer I assume you mean HA Active/Standby failover pair rather than a cluster? As the 2100 doesn't support clustering, only the 3000, 4000 and 9300 series hardware support clustering.

If Active/Standby failover pair, then yes they support S2S VPN (and remote access VPN) https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/vpn-s2s.html

https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/215470-site-to-site-vpn-configuration-on-ftd-ma.html

 

View solution in original post

3 Replies 3

@Chuck Reimer I assume you mean HA Active/Standby failover pair rather than a cluster? As the 2100 doesn't support clustering, only the 3000, 4000 and 9300 series hardware support clustering.

If Active/Standby failover pair, then yes they support S2S VPN (and remote access VPN) https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/vpn-s2s.html

https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/215470-site-to-site-vpn-configuration-on-ftd-ma.html

 

fpr 2000 series  dont support cluster but only HA active/passive 

And yes you can config vpn between HA and other peer' config vpn using active unit IP not standby that only what ypu need.

MHM

Chuck Reimer
Level 1
Level 1

Hi @Rob Ingram yes sorry HA not clustering. Thanks for help!

 

Review Cisco Networking for a $25 gift card