Sunday, June 6, 2021

Firepower FTD VPN VTI

I'm setting up a VTI VPN on Firepower FTD using FDM. There seems to be extremely limited settings available. How can you override the crypto domain which is expected/received? I think it defaults to 0.0.0.0/0 0.0.0.0/0 on VTI but what if the other side is sending something else and you want to match it?

I'm new to Firepower but if you go to the cli and you do a show run most of the config looks like ASA config. Can you make changes to this config like an ASA? I have read that you should only make changes in expert mode if for e.g. recommended by Cisco TAC.

Thanks



No comments:

Post a Comment