10-15-2025 08:55 PM
My FTD public facing interfaces are using "front door" VRF setups and I need to enable an interface for RA VPN. From what I have found the challenge is going to be leaking my internal routes to the "front door" VRF interface. I've seen examples using route-maps, dynamic routing protocols, redistribution etc.. so there seems to be several ways to accomplish this. Can anybody recommend a simple, straightforward option for doing this?
Thanks
10-15-2025 11:15 PM
Check one of the examples (see if that meets your requirement ?)
https://docs.defenseorchestrator.com/cdfmc/t-ravpn-vr-config-example.html
10-15-2025 11:22 PM
@tato386 "You cannot use interfaces that belong to user-defined virtual routers in policy-based site-to-site or remote access VPNs."
10-16-2025 06:36 AM - edited 10-16-2025 06:37 AM
"supported only on..." is sometimes not the same as "won't work".
10-17-2025 07:18 AM
update: FWIW, I setup RA using SSL and EntraID as IdP and enabled on the outside interface which is member of user defined VRF. I used static routes to leak inside networks to VRF and leaked VPN pool to global routing table and it seems to work. Maybe there are some features that don't work with this setup but for our purpose it seems to be working.
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide