Hi all,
We need to migrate multiple existing IPSEC S2S VPNS with a remote 3rd party that is replacing their remote gateway and changing peer IP. The VPN domain is not changing.
On our side, there is 4 HA clusters each with its own community to the remote peer.
To test one site, a new interoperable gateway object has been created for the new peer IP as well as a new community – the remote peer is implementing stricter encryption controls.
The existing interoperable gateway object will be taken out of the existing community and the new object will be added to the new community. The VPN domain will still be associated to the existing interoperable gateway object.
We can’t remove the VPN domain association from the original object as the object is a member of other VPN communities.
Is it possible to have the same VPN domain added to 2 interoperable device objects simultaneously without causing issues with regards to tunnel establishment? As mentioned, the interoperable device objects are not both members of any one community.
Regards,
Simon