Friday, June 4, 2021

Cisco ASA Firepower FTD VPN to Azure (VTI Route Based)

I'm trying to configure an IPSEC VPN to Azure using Firepower FTD (configuring with FDM, not FMC) I'm using the VTI tunnel option. FTD is running 6.7 so apparently it is supported. After lots of tinkering I'm only able to get Phase 1 up but not Phase 2. The debug doesn't show anything useful.

If I switch to policy based (on Azure and FDM sides) using the same proposals the VPN comes up.

Has anybody ever successfully setup a VTI VPN to Azure with FTD? It seems like a bug or something not supported. I'm using IKEv2.

Any feedback appreciated.

Thanks



No comments:

Post a Comment