05-20-2025 05:00 AM
Hi, I have a question.
I build VTI's to 2 separate destinations (2 tunnel interfaces) that I would logically like to have as my outside Zone.
Added to this a standard Inside and a DMZ.
What happens to the "Sessions" noted in the firewall if a session is started outgoing over the first Tunnel but the answer comes back over the 2nd tunnel - would it pass? Or does also the interface have to be the same?
I hope that this can be understood...
Thanks for the help.
Solved! Go to Solution.
05-20-2025 10:43 AM
@frazreid2 I'm sorry I automatically assumed you were referring to VTI on FTD. I've not had this scenario before on a IOS-XE router using VTI with ZBFW to be honest. There doesn't appear to be much information in the ZBFW design guide, but perhaps you "pass" traffic instead of "inspect", you would have to amend the policy to explictly permit traffic. Else log a call with Cisco TAC and see if they have a solution.
05-20-2025 05:18 AM - edited 05-20-2025 05:20 AM
@frazreid2 use ECMP traffic zones.
You can associate VTI interfaces with ECMP zones and configure ECMP static routes to achieve the following:
Load balancing (Active/Active VTIs)—Connection can flow over any of the parallel VTI tunnels.
Seamless connection migration—When a VTI tunnel becomes unreachable, the flows are seamlessly migrated to another VTI interface that is configured in the same zone.
Asymmetric routing—Forward traffic flow through one VTI interface and configure the reverse traffic flow through another VTI interface.
05-20-2025 07:02 AM
Hi Rob - not sure how to configure ECMP on a Catalyst C8300 router with VTI's.
05-20-2025 10:43 AM
@frazreid2 I'm sorry I automatically assumed you were referring to VTI on FTD. I've not had this scenario before on a IOS-XE router using VTI with ZBFW to be honest. There doesn't appear to be much information in the ZBFW design guide, but perhaps you "pass" traffic instead of "inspect", you would have to amend the policy to explictly permit traffic. Else log a call with Cisco TAC and see if they have a solution.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide