09-29-2022 10:59 PM
When you setup a Site-to-Site VPN tunnel between an ASA and FTD, do both ends have to be setup using the same type of configuration as in Policy-Base or Route Base? Or can one end be configured with Policy Base and the other end setup as Route Base (VTI)?
Thx in advance for any help given.
09-30-2022 01:29 AM
Good question, I never tried to play with this on my lab, however, I think both should match the type, because as part of the negotiation between the firewalls to establish the tunnel would be related to the proxy domains which are the subnets defined in the crypto ACLs.
09-30-2022 01:53 AM
@manofsteel03 I think this is possible, never tried it, you could set the Policy Based crypto ACL to match 0.0.0.0/0. Though why? I don't think this would be a good design, use a Route Based or Policy Based VPN, not a mixture of both.
FYI, On IOS-XE routers (not ASA/FTD), there is this newish option of using Multi-SA VTI - https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/214728-configure-multi-sa-virtual-tunnel-interf.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide