08-22-2023 06:11 AM
We have a situation where:
1) Customer is replacing their Headend Firewall / VPN device (SonicWall); with FTD 1000 using FTD.
2) They have several Dynamic S2S VPNs on Draytek routers.
3) In testing we found out that the Headend FTD when using dynamic S2S VPNs had to use the same PSK for all dynamic sites for tunnels to establish.
4) The customer does not want to use same PSK on all VPNs, this would be a "downgrade" in their current security, which we agree.
5) This was referred this to TAC who offered a flex-config solution where we would have to add 80 lines of config to stipulate the tunnel-groups with local and remote PSKs. When we tested in a lab and with the customer this did not work very well. I feel it would be OK for a couple of VPNs but gets messy with a lot. For example it seemed we had remove and re-add flex config if we made a change to any operational VPNs, so seemed like it could cause issues.
6) We asked TAC if RSA keys would work and TAC said it should, we thought this more elegant as no flex config. We needed the remote routers (Draytek), to support RSA certificates which they do.
7) The Drayteks fail to authenticate using RSA but the FTD seems to accept the certificate. We found this from debugs on FTD and Syslogs on Draytek.
I just wandered if anyone can suggest a solution as I have spent hours / days trying to get something working and hitting a brick wall. The customer purchased FTD as a premium product and to them its just like the FTD cannot even do what the Sonicwall and Drayteks could do.
We do have ticket open with Draytek but they are not very responsive as the customer does not have premium support, they simply work in the current solution so the customer just replaces them if they get a hardware failure.
08-30-2023 02:05 PM
If you could post the debugs you see on the FTD and the Draytek, it would be easier for the community to look into it and maybe give you some things to try out.
08-30-2023 11:56 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide