09-24-2024 10:25 AM
I need to connect an Out of Band (OOB) network across a site-to-site VPN already established.
Running FMC (v7.2.8) managed FTD (v7.2.5) firewall.
I have searched, but I've had no luck finding any information.
Thanks, Cliff
09-24-2024 10:28 AM
This link for asa but it also work for ftd check it
MHM
09-24-2024 10:49 AM
Thanks, but not sure if this is what I am looking for, as I see this requires NAT, and I need full layer 2, so broadcasts etc. cross to the other side without NAT.
09-24-2024 11:25 AM
As I know ftd not support l2tpv3
So if you have any device support l2tpv3 connect to both ftd ypu run l2tpv3 over vpn between ftd.
MHM
09-30-2024 02:17 PM
I found that the FTD’s can do VxLAN on their own https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/221043-configure-vxlan-interfaces-on-secure-ftd.html (read but not implemented yet).
But I could use a little more detail on the exact connectivity to the inside switches. The actual connectivity to the FTD (does it need its own interface, or can it be a sub-interface on my internal LAN interface.
-cliff
10-01-2024 06:47 AM
Also, the document states “The configure section assumes that the underlay network is already configured on threat defense via the Secure Firewall Management Center. This document is focused on overlay network configuration.” My underlay network is working, but is it setup correctly for VxLAN?
Just a brief: SW1-{port1} --> FTD-{interfaceA} <—>FTD-{interfaceB} --> SW2-{port2}
Is SW-{port1} an access port or trunk? Is FTD-{interfaceA} a dedicated interface or can it be a Sub-Interface? Same with {port2} and {interfaceB}?
Thanks-
10-01-2024 06:51 AM
Indeed ftd use in DC and with vxlan let check your requirements with ftd and vxlan
Update you tonight
Thanks
MHM
10-02-2024 12:02 AM
Can you check if you use vti which give you new interface which later you can use for vxlan
MHM
10-02-2024 07:04 AM
When logging on the CLI of each FW, I should be able to ping each side of the VTEP interface (172.24..101.1 <--> 172.24.107.1) But it is failing.
I am not sure what the issue is. I have attached a an updated image and PDF (not sure which is best), edited FW configs are in the image.
Thanks-
10-24-2024 07:48 AM
I found the the our FP2110's do not support VxLAN in routed mode.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide