Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Benefits

Updated: February 5, 2026

Overview

Highlights the benefits of using DVTI in Cisco Secure Firewall, including simplified configuration and management, scalability, dynamic routing, redundancy, load balancing, and secure connectivity across branch and hub deployments.

The benefits of using a DVTI-based VPN in a hub and spoke topology are:

  1. Simplified Configuration: VTI simplifies the configuration of VPN tunnels by providing a logical interface that represents the tunnel itself. This eliminates the need for complex crypto map or access list configurations typically associated with traditional VPN setups.

  2. Simplified Management: It is easy to manage peer configurations for large enterprise hub and spoke deployments. Only one dynamic VTI is configured on the hub for multiple static VTIs configured on the spokes.

  3. Scalability: VTI allows for easy scalability. Addition of new spokes does not require any additional VPN configuration on the hub. You may need to update NAT and routing configurations depending upon the setup.

  4. Dynamic Routing Support: VTI supports dynamic routing protocols such as Open Shortest Path First (OSPF) allowing for the dynamic exchange of routing information between VPN endpoints. This enables efficient routing decisions based on real-time network conditions.

  5. Dual ISP Redundancy: SVTI supports backup VTI tunnels.

  6. Load balancing: SVTI supports load balancing of VPN traffic using ECMP.