Guidelines for Distributed Site-to-Site VPN
Firewall Mode
Distributed site-to-site VPN is supported in routed mode only.
Additional Guidelines
-
Only IKEv2 IPsec site-to-site VPN is supported in distributed site-to-site VPN mode. IKEv1 is not supported. IKEv1 site-to-site is supported in centralized VPN mode.
-
Inter-site clustering is not supported.
-
To view FlexConfig features that are also not supported with clustering, for example many inspections, see the ASA general operations configuration guide. FlexConfig lets you configure many ASA features that are not present in the Firewall Management Center GUI. See FlexConfig Policies.