Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Configure the Backup VTI Interface on the Spoke Node

Updated: February 5, 2026

Overview

Provides instructions for configuring a backup static VTI for spoke devices to maintain VPN connectivity with the hub and ensure continuous traffic flow.

Firewall Threat Defense supports the configuration of a backup tunnel for the route-based (VTI) VPN. When the primary VTI is unable to route the traffic, the traffic in the VPN is tunneled through the backup VTI.

Procedure

1.

Choose Devices > Site-to-site VPN to view the configured Corporate-VPN VPN topology and click the Edit (edit icon) icon. The Edit VPN Topology window appears.

2.

In the Spoke Nodes section, click the Edit (edit icon) icon for the NGFWBR1 node. The Edit Endpoint dialog box appears.

3.

Click the Add Backup VTI link to add the secondary VTI tunnel. The link displays the Backup VTI section.

Screenshot of backup VTI configuration in Firewall Management Center
4.

Click + next to the Virtual Tunnel Interface drop-down list to add a new VTI.

The Add Virtual Tunnel Interface dialog box appears with the following pre-populated default configurations.

  • Tunnel Type is auto-populated with Static.

  • Name is auto-populated as <tunnel_source interface logical name>+ static_vti +<tunnel ID>. For example, outside_static_vti_2 .

  • The Enabled checkbox is checked by default.

  • Select Tunnel_Zone from the Security Zone drop-down list.

  • Tunnel ID is auto-populated with a value as 2.

  • Select GigabitEthernet0/3 (outside2) from the Tunnel Source drop-down list. Select the IP address of the outside 3 interface as 198.19.40.4 from the drop-down list next to it.

  • IPsec Tunnel Mode is set to IPv4, by default.

  • IP address can either be a static IP address or a borrow IP. We recommend that you configure the Borrow IP for the static interface from a loopback interface. To add a loopback interface, click select Loopback 1(Spoke_Tunnel_IP) from the drop-down list.

Click OK to save the VTI. A message is displayed that confirms the VTI is created successfully. Click OK.

The backup VTI Interface is set to outside_static_vti_2(169.254.20.1).

5.

Click OK to save the spoke configuration.

6.

Click Save to save the VPN topology.