Solved

How to have Site to site VPn on Dynamic Ip address

Posted on 2004-08-30
3
847 Views
Last Modified: 2008-03-06
Hi All

I am using PIX 515 E at one end and PIX 506 at another end.At bothe ends i dont have static Ip address hence i am using DDNS (dynamic DNS) to resolve the current IP address on teh firewall for enabling the Remote dialin VPN.its working fine as well.

Now if i want have a SITe-SITe Vpn working between these two sites how can i do it with this dynamic IP address?  I tried using Host name which configuring the Peer host name in the VPn policies but it goes to "Resolving domain name" and terminates saying that hostname cannot be resolved while that domain name is running at another site..

Is i am missing something in the configuration?
Regards and thanks

Samir.
0
Comment
Question by:samprav
3 Comments
 
LVL 3

Accepted Solution

by:
frieked earned 150 total points
ID: 12000190
Sorry to break it to you but the pix currently can not do name resolution although dns requests can be configured to pass through the pix...so dynamic dns is not an option...I pulled this answer straight off cisco's site: Q. Can the PIX do name resolution?
A. While a properly configured PIX does permit Domain Name System (DNS) traffic through to allow for inside and outside devices to do DNS, the PIX itself does not resolve names.

As far as I know it is not possible to set up a site to site vpn between 2 dynamic hosts...because what happens in the case where both hosts get new IP addresses at the same time, neither one knows how to contact the other and the VPN is dropped.

You need one pix to act as the static and set it up to accept dynamic connections like so:
!--- ISAKMP Policy for accepting dynamic connections from remote PIX
isakmp key ******** address 0.0.0.0 netmask 0.0.0.0

See this page for full instructions on setting up a static to dynamic vpn between 2 pix's:
http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_configuration_example09186a0080094680.shtml

I am going to assume you are aware of the security risk of allowing dynamic vpn connections so I won't get into that.

One other note...depending on how often your IP changes you can pretend one or both of your pix's has a static IP address.  I have optimum online and my IPs are dynamic but change very infrequently so I just update my VPNs whenever they change.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Just about everyone has an old PC laying around.  Ask anyone in the IT industry, whether they are a professional or play in it as a hobby.  From outdated Desktops to cheap "throwaway" laptops, they are all around and not as hard to "fix up" as you m…
I don't know if many of you have made the great mistake of using the Cisco Thin Client model with the management software VXC. If you have then you are probably more then familiar with the incredibly clunky interface, the numerous work arounds, and …
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question