Provides instructions for creating a route-based site-to-site VPN between a hub and a branch site using Firewall Management Center (FMC).
You can configure a route-based site-to-site VPN between two nodes. To configure a VTI-based VPN you need virtual tunnel interfaces at both the nodes of the tunnel.
For managed spokes, you can configure a backup static VTI interface along with the primary VTI interface.
Procedure
What to do next
After you configure VTI interfaces and VTI tunnel on both the devices, you must configure:
-
A routing protocol to route the VTI traffic between the devices over the VTI tunnel. See Configure OSPF on the Hub Node and Configure OSPF on the Spoke Node.
-
An access control rule to allow encrypted traffic. See Configure the Access Control Policy.