01-17-2024 02:09 AM
Hi all,
I have configured Policy Based Site-to-Site VPN from from local network and outside (ISP1) interface to remote network, and it's working. I have configured Access COntrol and NAT policy, everything is working fine, but..
When ISP1 is down traffic is switched to ISP2, it's based on IP SLA, but tunnel not encrypt traffic.
in tunnel configuration i have selected two outside interfaces ISP1 and ISP2
SLA and failover are working fine, when isp1 is down routing table is changing but tunnel doesn't reconnects, even when i manually clear session. Remote site is configured as dynamic (huawei)
Do you have any experience with this configuration?
Solved! Go to Solution.
01-23-2024 05:51 AM
Hi all,
thanks for questions and your time.
I tested it in the virtual environment and everything is working fine, when sla is down traffic is switched to ISP2 and tunnel works fine, so problem is not at configuration FDM but on remote side
01-17-2024 02:19 AM
as I see you use static not dynamic for remote site ?
01-17-2024 02:36 AM
For firepower remote site is configured as static (remote network has one ip address behind BGP)
remote site is configured as dynamic to allow tunnels from more then 1 ip
quick scheme:
01-17-2024 02:52 AM
Did you add ISP2 outside interface as backup in fdm vpn ?
MHM
01-17-2024 03:01 AM
yes, fdm looks like below:
01-17-2024 05:22 AM
This should work. Running config from FTD (or at least "show run crypto" + "show run nat") would be more helpful than a picture from FDM to begin with.
01-17-2024 06:39 AM
NAT policy <<- are you add NO-NAT
from INside Zone to OUTside1 Zone
froom INside Zone to OUTside2 Zone
MHM
01-17-2024 06:46 AM
i met like as issue with Azure. you want to get two tunnel active and standby, destination side is one side, or two side ? tunnel remote network is same subnet ?
01-17-2024 07:49 AM
I ask him he confirm that Hawaii use dynamic
also the FTD not encrypt
so the traffic in FTD never hit the ACL
MHM
01-23-2024 05:51 AM
Hi all,
thanks for questions and your time.
I tested it in the virtual environment and everything is working fine, when sla is down traffic is switched to ISP2 and tunnel works fine, so problem is not at configuration FDM but on remote side
01-23-2024 05:58 AM
Thanks for update us
Glad issue is solved
Have A nice day
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide