Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Configure an ECMP Zone for the Primary and Secondary VTI Interfaces

Updated: February 5, 2026

Overview

Provides instructions to configure an ECMP zone for DVTI-based VPNs to distribute traffic and optimize connectivity in Firewall Management Center (FMC).

Configure ECMP on the primary and secondary static VTI interfaces on the branch node for link redundancy and for load balancing the VPN traffic.

Procedure

1.

Choose Devices > Device Management, and edit the Threat Defense device (NGFWBR1).

2.

Click the Routing tab on the interface view of NGFWBR1.

3.

Click ECMP.

4.

Click Add.

5.

In the Add ECMP box, enter a name, ECMP-VTI for the ECMP zone.

6.

To associate interfaces, select the interfaces outside_static_vti_1 and outside_static_vti_2 under the Available Interfaces box, and then click Add.

Screenshot of in ECMP configuration in Firewall Management Center
7.

Click OK.

The ECMP page now displays the newly created ECMP zone.

8.

Click Save.