cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
656
Views
0
Helpful
2
Replies

Site to Site between FTD and VPN headend with Dynamic IP

David0531
Level 1
Level 1

Hello everyone,

I am trying to configure Site-to-Site VPNs as below:

Site A:

FTD v6.7  In/Out Static IP

Site B:

Modem external interface FQDN "my.exemple.com (IP 93.229.6.x it always changes)" - internal interface DHCP 192.168.178.0/24

FTD v6.7 receives for external interface from Modem IP 192.168.178.0/24.

How to configure with FMC? How connect and connect DDNS into Site-A firewall? 

2 Replies 2

No need ddns 

You can use topolgy hub and spoke ipsec 

Hub with static IP spoke with dynamic IP

This I think solve your issue

MHM

tvotna
Spotlight
Spotlight

Unlike IOS routers ASA and FTD do not currently support real-time resolution of IPSec tunnel peer (CSCus37350). So, initiate tunnel from Site B to Site A. ASA example: https://www.cisco.com/c/en/us/support/docs/ip/internet-key-exchange-ike/118743-configure-asa-00.html. For FTD search for "dynamic crypto-map": https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/vpn-s2s.html