Understand how to configure network tunnels with Cisco Secure Firewall to support site-to-site VPN between Firewall Threat Defense devices and Secure Access through Cisco Secure Firewall Management Center.
Cisco Secure Firewall is a family of threat-focused next-generation firewalls. It can be managed centrally through Cisco Secure Firewall Management Center or through the on-box manager Secure Firewall Device Manager (FDM). This guide covers the steps to configure site-to-site VPN between FTD devices and Secure Access through Cisco Secure Firewall Management Center.
Until version 6.7, FTD only supports policy-based VPN (Crypto-map). Version 6.7+ supports Virtual tunnel interface (VTI), version 7.1+ supports IKE identity and policy-based routing (PBR) through graphic interface.
The Secure Firewall configuration process consists of the following steps.
-
Add Network Object
-
Add Traffic Selector ACL
-
Configure Site-to-Site VPN
-
Configure NAT Policy
-
Configure Access Policy