Configure Endpoints for a Hub and Spoke Topology
You can create a route-based site-to-site VPN using dynamic VTI only for hub and spoke topologies. The hub can use only a dynamic VTI and the spokes can use only static VTI interfaces. You can also configure an extranet device as a hub.
Configure the following parameters to configure endpoints for a route-based site-to-site VPN for the Hub and Spoke topology nodes:
Before you begin
Configure the basic parameters for a hub and spoke topology in a route-based VPN as described in Create a Route-based Site-to-Site VPN and click the Endpoints tab.
Procedure
Step 1 | Under Hub Nodes: |
Step 2 | Under Spoke Nodes: |
What to do next
-
(Optional) Specify the IKE options for the deployment as described in Threat Defense VPN IKE Options.
-
(Optional) Specify the IPsec options for the deployment as described in Threat Defense VPN IPsec Options.
-
(Optional) Specify the Advanced options for the deployment as described in Threat Defense Advanced Site-to-site VPN Deployment Options.
-
Click Save.