cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
294
Views
5
Helpful
1
Replies

Mesh Topology S2S changes

keithcclark71
Level 3
Level 3

I have migration from current ASA to ASA S2S tunnels into FMC as a mesh topology. For reasons of migration i have to move into the FMC MESH now using IKE1. In theory once I get all the sites up and running into the mesh within FMC I should be able to make changes to the mesh that would apply to all my sites such as changing the passphrase and moving to IKE2 in a single deployment which i would thing cause a drop in the production tunnels and re-establishment of the tunnels with the new IKE2 settings?

1 Accepted Solution

Accepted Solutions

@keithcclark71 yes tunnels would drop. If the current tunnels were established using IKEv1, you change the configuration to use IKEv2 - the firewalls will need to establish IKEv2 SA and IPSec SA using the new settings. Best do it out of hours.

View solution in original post

1 Reply 1

@keithcclark71 yes tunnels would drop. If the current tunnels were established using IKEv1, you change the configuration to use IKEv2 - the firewalls will need to establish IKEv2 SA and IPSec SA using the new settings. Best do it out of hours.