01-24-2025 04:09 AM
Hi,
I have an RAVPN solution deployed at two different sites. They each are supposed to use different address pools but when I change one pool it changes the other.. how do I get around this?
Site 1
The address pool for site one should be 192.168....
Site 2
The address pool for site 2 should be 10.116.89.16 - 253 when I change it in the site two configuration it changes the site 1 also..
Solved! Go to Solution.
01-24-2025 04:35 AM
We start with pool and now we end to change all VPN.
Friend add new vpn profile totally new abd use new object for new VPN pool.
In some point the fmc use same vpn config for both ftd sites
MHM
01-24-2025 04:11 AM
That must not happend unless you deploy change to group not to standalone ftd.
MHM
01-24-2025 04:14 AM
Just thinking would I need to create a new group policy instead of using the same for both sites?
01-24-2025 04:17 AM
Sure correct.
In end fmc push config to both site ftd' if yoh use same object-group then fmc will push same pool to both site ftd.
MHM
01-24-2025 04:17 AM - edited 01-24-2025 04:18 AM
@NetworkMonkey101 it looks like you are referencing the same IP address pool object? Create a different IP address pool and reference the new address pool on the connection profile.
Alternatively if you want to use the same address pool object, you could use the "allow overrides" option and define a different address range per appliance.
01-24-2025 04:22 AM - edited 01-24-2025 04:24 AM
Hi Rob, I change to pool at site 2 within the connection profile and site 1 is also change at the same time.. I think it's because I am using the same profile for each one, will test and update. Thanks!
01-24-2025 04:29 AM
@NetworkMonkey101 yes.
Even if you are using the same object you can use the "Allow override" option and apply the different IP range to different FTDs. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/vpn-remote-access.html
01-24-2025 04:32 AM
So I have create another group policy and set the IP pool within it but when in the connection profile if I set the address pool it over writes the other site still...
Whatever I set it to above overwrites the other..
01-24-2025 04:35 AM
We start with pool and now we end to change all VPN.
Friend add new vpn profile totally new abd use new object for new VPN pool.
In some point the fmc use same vpn config for both ftd sites
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide