Guidelines for distributed site-to-site VPN

Firewall mode

Distributed site-to-site VPN is supported in routed mode only.

Unsupported inspections

These types of inspections are not supported or are disabled in distributed site-to-site VPN mode:

  • CTIQBE and DCERPC

  • H323, H225, and RAS

  • IPsec pass-through

  • MGCP, MMP and NetBIOS

  • PPTP and RADIUS

  • RSH and RTSP

  • SCCP (Skinny) and SUNRPC

  • TFTP

  • WAAS, WCCP, XDMCP

Additional Guidelines

  • Only IKEv2 IPsec site-to-site VPN is supported in distributed site-to-site VPN mode. IKEv1 is not supported. IKEv1 site-to-site is supported in centralized VPN mode.

  • Inter-site clustering is not supported.

  • To view FlexConfig features that are also not supported with clustering, for example many inspections, refer to ASA general operations configuration guide. FlexConfig lets you configure many ASA features that are not present in the Cloud-Delivered Firewall Management Center GUI. For more information, refer to FlexConfig policies.