cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3661
Views
0
Helpful
12
Replies

Firepower FMC VPN - backup peer?

mhmservice
Level 1
Level 1

Does anyone know if it's possible to configure a backup peer with the firepower management center VPN configuration - ideally in full mesh topology

 

On ASA this would be configured on the crypto-map something like "crypto map outside_map 10 set peer 1.1.1.1 2.2.2.1"

 

It's really a big limitation of the product if we can only have a single internet connection in each site (or at least without using an additional router/DMVPN/etc), as I was hoping to keep the number of devices and complexity to a minimum

 

Thanks in advance

12 Replies 12

I think there is no backup peer ip address. I have check my fmc for FTD. nope.

please do not forget to rate.

Hi,

What version are you running? This bug CSCvg43238 indicates it's fixed in 6.2.3

 

HTH

Hi I am on 6.1.0

please do not forget to rate.

I'm testing with 6.2.3,

 

Where would I configure this?

try using the flex config

please do not forget to rate.

Hi,

See this link. It states for IKEv1, you can define a backup peer for point-to-point Extranet VPNs.

 

HTH

Thanks for that, my understanding of Extranet device is that it should be used for devices that cannot be managed in FMC (but all my devices can be managed on FMC), is there a way to do this and still have them under FMC's management?

There doesn't appear to be (that I am aware of) an elegant or obvious way of configuring this yet, for FTD's managed by the same FMC. Whether the previous suggestion of using FlexConfig to configure an additional peer works I dont know, as I have not tested.

HTH

OK thanks, thats the conclusion i've come to as well, it's a real shame that FMC/FTD appears to be lacking these enterprise-level VPN features... I don't think many customers would be happy with being limited to a single WAN connection for their VPNs

 

I will have a look at FlexConfig but it already seems like a workaround that I wouldnt really be happy to put into production, my aim for my project is simplify our management and using additional scripts to fix missing functionality isn't helping that..

Yes mate agree only option is flex config at the moment 

please do not forget to rate.

In 6.2.3 and above, this feature is available.

 

In the peer definition, when you choose an Extranet device, you can supply two IP's separated by a comma, for the IP address.  This will define them as redundant peers for the same VPN.

 

malecona
Level 1
Level 1

Hola , su equivalente en FMC es crear 2 túneles con la misma configuración , donde en cada uno de los 2 túneles solo va a variar la interface  outside que uses , ejemplo uno lo creas con la outside1 y el otro con la outside2 .

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: