Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
@sahdogra ECMP is supported on route based VPN using a static VTI, so you'd need to reconfigure. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/760/management-center-device-config-76/vpn-s2s.html
@SecSuperAdmin the ACP is for traffic "through" the FTD, not "to" the FTD itself, so scanning the FTD would not be blocked by the ACP.
You can secure RAVPN with https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222383...