Configure Tunnels in Secure Access
From Secure Firewall 7.1+, FTD can authenticate to Secure Access by using a Pre-Shared Key (PSK) and IP or FQDN IKEv2 identity. If the Secure Firewall is behind a NAT device, FQDN identity is the only possible option.
Virtual tunnel interface is available from Secure Firewall 6.7+ with Policy Based Routing (PBR) through FlexConfig. Secure Firewall 7.1+ adds Per Tunnel Identity and Policy Based Routing via graphic interface.
Follow the steps in Add Network Tunnel Group to add Secure Firewall VTI and PBR to Secure Access.
Note: When supported by the device, FQDN is always the preferred option.
The new tunnel appears in Secure Access with a status of UnEstablished. The tunnel status is updated once the first IKEv2 INIT message containing the tunnel identity is received in one of the Secure Access data centers.