cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
434
Views
3
Helpful
4
Replies

FTD RA WebVPN with VRF interface

tato386
Level 6
Level 6

My FTD public facing interfaces are using "front door" VRF setups and I need to enable an interface for RA VPN.  From what I have found the challenge is going to be leaking my internal routes to the "front door" VRF interface.  I've seen examples using route-maps, dynamic routing protocols, redistribution etc.. so there seems to be several ways to accomplish this.  Can anybody recommend a simple, straightforward option for doing this?  

Thanks   

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

Check one of the examples (see if that meets your requirement ?)

https://docs.defenseorchestrator.com/cdfmc/t-ravpn-vr-config-example.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

tato386
Level 6
Level 6

"supported only on..." is sometimes not the same as "won't work".     is it worth giving it shot to see what happens?

tato386
Level 6
Level 6

update:  FWIW, I setup RA using SSL and EntraID as IdP and enabled on the outside interface which is member of user defined VRF.  I used static routes to leak inside networks to VRF and leaked VPN pool to global routing table and it seems to work.  Maybe there are some features that don't work with this setup but for our purpose it seems to be working.

Thanks