Create a VPN cluster to logically group hub and branch firewalls and automatically
secure connections between these devices.
| Where Can I Use This? | What Do I Need? |
To configure Auto VPN, you must create a VPN cluster to determine which branch
firewalls communicate with which gateway devices and automatically create secure
connections between the gateway and branch firewalls. VPN clusters are logical
groupings of managed firewalls that
supports
a hub and spoke topology, so consider such things as geographical location or
function when logically grouping your firewalls.
An autogenerated VPN configuration
provides secure connectivity of up to 500 devices.
The routing configuration is automatically generated when Auto VPN is configured.
This includes creating the IPSec tunnels between your gateway and branch devices,
and autogenerating the
Border
Gateway
Protocol
AS number and Router ID.
For HA deployments, Auto VPN generates an
appropriate configuration for the active and passive HA peers (for both branch and
hub HA pairs) automatically. This keeps the active and passive device configurations
in synchronization and thus enables the HA failovers to be seamless between the HA
pairs. Auto VPN can distinguish between the individual and HA hub/branch devices and
generates the appropriate configuration for the HA pairs automatically.
For the Auto VPN, to generate the configuration on the hub/branch HA pairs
automatically, you must ensure the following: