Active-Active VPN Gateway Azure to a single on-prem ASAv using VTI

Tommy Alex 1 Reputation point
2021-02-19T21:14:42.1+00:00

We are trying to use Active-Active VPN Gateway on Azure to connect to a Cisco ASAv (single) . The problem is that the ASA uses a different BGP ip for each tunnel interface. But the Azure configuration only has an option to set a single BGP peer in the local network gateway setting. What are options to make this work using active /active to a single box with two bgp peer ips or other options ?

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,393 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. GitaraniSharma-MSFT 47,686 Reputation points Microsoft Employee
    2021-02-22T15:26:10.66+00:00

    Hello @Tommy Alex ,

    As per Cisco ASA 9.8+ VTI documentation, currently, VTI is only supported in single-context, routed mode.
    70640-asa-vti-aa.jpg

    You can also find this information in Cisco ASA VTI doc :
    Context Mode
    Supported in single mode only.

    So, it looks like this is not supported. However, I will check with Azure VPN PG to see if there are any workarounds to bypass this constraint.

    Kindly let us know if the above helps or you need further assistance on this issue.

    ----------------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.