Choose the configuration that suits your situation:
- Route-based configuration: Recommended if your Cisco ASA is running version 9.7.1 or newer.
- Policy-based without VPN filters: Recommended if your Cisco ASA is running a version older than 9.7.1, and you're not already using VPN filters.
- Policy-based with VPN filters: Recommended only if you're already using VPN filters.
Cisco ASA versions 9.7.1 and newer support route-based configuration, which is the recommended method to avoid interoperability issues.
If you want tunnel redundancy with a single Cisco ASA device, you must use route-based configuration. With policy-based configuration, you can configure only a single tunnel between your Cisco ASA and your dynamic routing gateway (DRG), even though Oracle provides configuration information for two tunnels.