cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
117
Views
0
Helpful
2
Replies
Beginner

VPN with Firepower/Anconnect over 2 different sites w/redundancy?

Hi everyone.

This one is a bit tricky.

 

We have 2 different Firepower devices, 21xx and 41xx, on different locations. The idea was to have them work independent from each other, but the customer wants some kind of automatic redundancy in case one fails. The current solution they have has the clients having to change the VPN concentrator IP address on their VPN client to connect to the other firewall (not Cisco).

 

Is there. way to do this? Perhaps leaving the IP address assignment to a DHCP server inside the LAN, and then some routing protocol to announce that IP address on one working firewall?

Really, I was just thinking of using separate IP address pools on each firewall, and instead relying on some kind of round robin feature on the AnyConnect client. Does this exist?

 

Thanks for your time.

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
RJI Advisor
Advisor

Re: VPN with Firepower/Anconnect over 2 different sites w/redundancy?

Hi,

You can define a backup server which in the event the primary FTD/ASA fails, AnyConnect will connect to the backup FTD/ASA. This is configured using the AnyConnect VPN Profile Editor. Example below.

 

ac vpn.PNG

 

Why does the VPN Pool assignment matter? As you said you could get DHCP to issue the IP address to the clients and then distribute that using a routing protocol.

 

HTH

View solution in original post

2 REPLIES 2
Highlighted
RJI Advisor
Advisor

Re: VPN with Firepower/Anconnect over 2 different sites w/redundancy?

Hi,

You can define a backup server which in the event the primary FTD/ASA fails, AnyConnect will connect to the backup FTD/ASA. This is configured using the AnyConnect VPN Profile Editor. Example below.

 

ac vpn.PNG

 

Why does the VPN Pool assignment matter? As you said you could get DHCP to issue the IP address to the clients and then distribute that using a routing protocol.

 

HTH

View solution in original post

Highlighted
Beginner

Re: VPN with Firepower/Anconnect over 2 different sites w/redundancy?

Yeah, I was thinking ahead with the vpn pools, but I assume it doesn't matter the IP address the clients get since in the actual configuration they do have separate pools per concentrator.
The answer you gave me is the one I needed. Thanks for your time.