cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1639
Views
5
Helpful
7
Replies

ikev2 S2S secondary VPN peer - Firepower 6.6

ryan14
Level 1
Level 1

Per Cisco documentation it is reported that Firepower version 6.6 supports a backup secondary peer. I tried to configure another peer but do not see the option to do so. Has anyone else had success?

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/firepower_threat_defense_site_to_site_vpns.html

 

Support for IKEv1 and IKEv2 back-up peer configuration for point-to-point extranet and hub-and-spoke VPNs.

1 Accepted Solution

Accepted Solutions

Here some screenshots:

 

image.pngimage.png


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

View solution in original post

7 Replies 7

Francesco Molino
VIP Alumni
VIP Alumni
Hi

If you are in point to point VPN and you picked extranet as remote device, in the ip address field, you can enter the primary ip and then comma followed by backup ip like 1.1.1.1,2.2.2.2

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Are you saying go to devices -> vpn -> site to site, add vpn menu -> then go to firepower device? If I go to edit an existing topology it doesn't allow you to add another interface (backup circuit).

When you create a new vpn point to point, the local device is your ftd and remote device is extranet. Then, by choosing extranet, you have a field showing up where you need to fill in the remote ip. In that field you can put both IPs separated by a comma.
Here a documentation explaining that:
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/firepower_threat_defense_site_to_site_vpns.html#id_15287

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Why is it that when I go to add vpn -> firepower threat defense device and want to add a point to point with 2 FTDs in my FMC, I can only have one outside interface from each side when multiple outside interfaces need to be added?

 

If I go to add vpn -> firepower device I can configure multiple interfaces but the device in the drop down I do not see any of my FTDs which are part of FMC, it just shows other.

 

 

Here some screenshots:

 

image.pngimage.png


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Thanks for taking the time to do that, it was helpful. I didn't see the 'extranet' option that was at the bottom of the drop down. Is there any reason why the FMC can't 'natively' obtain the interface info from drop downs if those interfaces are specified in the FMC? This is how we do our primary point to point tunnels where you can select which interfaces from drop down menus we want to use for the tunnel endpoints. Why can't we just do this for the secondary?

 

The other interesting thing I noticed is that my FMC doesn't show route based vpn under topology. I just see "Topology Name" and then "Network Topology" directly under but no button for VTI as yours shows. I am running 6.6.0.1.

Extranet device can be your own remote ftd or a remote device not managed by FMC. This is the only way to add the backup ip.

For VTI, it is not in official release. I'm running a beta code that's why you saw it in my screenshot. Sorry about that.


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question