08-24-2020 12:53 PM - edited 08-24-2020 12:59 PM
Per Cisco documentation it is reported that Firepower version 6.6 supports a backup secondary peer. I tried to configure another peer but do not see the option to do so. Has anyone else had success?
Support for IKEv1 and IKEv2 back-up peer configuration for point-to-point extranet and hub-and-spoke VPNs.
Solved! Go to Solution.
08-28-2020 03:30 PM
Here some screenshots:
08-24-2020 07:56 PM
08-26-2020 12:48 PM
Are you saying go to devices -> vpn -> site to site, add vpn menu -> then go to firepower device? If I go to edit an existing topology it doesn't allow you to add another interface (backup circuit).
08-26-2020 07:54 PM
08-27-2020 04:57 AM
Why is it that when I go to add vpn -> firepower threat defense device and want to add a point to point with 2 FTDs in my FMC, I can only have one outside interface from each side when multiple outside interfaces need to be added?
If I go to add vpn -> firepower device I can configure multiple interfaces but the device in the drop down I do not see any of my FTDs which are part of FMC, it just shows other.
08-28-2020 03:30 PM
Here some screenshots:
08-31-2020 11:05 AM
Thanks for taking the time to do that, it was helpful. I didn't see the 'extranet' option that was at the bottom of the drop down. Is there any reason why the FMC can't 'natively' obtain the interface info from drop downs if those interfaces are specified in the FMC? This is how we do our primary point to point tunnels where you can select which interfaces from drop down menus we want to use for the tunnel endpoints. Why can't we just do this for the secondary?
The other interesting thing I noticed is that my FMC doesn't show route based vpn under topology. I just see "Topology Name" and then "Network Topology" directly under but no button for VTI as yours shows. I am running 6.6.0.1.
09-01-2020 08:13 PM
Extranet device can be your own remote ftd or a remote device not managed by FMC. This is the only way to add the backup ip.
For VTI, it is not in official release. I'm running a beta code that's why you saw it in my screenshot. Sorry about that.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide