Solved

Cisco site to site vpn using fqdn

Posted on 2014-04-03
4
743 Views
Last Modified: 2014-07-03
Is it possible for two Cisco ASA 5500 series to do site to site vpn using FQDN instead of IP addresses? If not, any idea on how to configure automatic failover between two locations with site to site vpn, each with an ASA 5500 series, and each ASA has 2 different internet connections? Thank you.
0
Comment
Question by:alex9420
  • 2
4 Comments
 
LVL 15

Expert Comment

by:max_the_king
ID: 39977528
Hi,
you can set multiple peers in tour cryptomap: for example:

crypto map your_map 10 set peer 1.2.3.4 5.6.7.8

that way you tell asa to check for remote peer 1.2.3.4 and, in case it does not respond, it will check on ip 5.6.7.8

you can do this on any asa peer you want to get into the tunnel

hope this helps
max
0
 

Author Comment

by:alex9420
ID: 39990485
Max,
Thank you for your reply. Your suggestion will work if all the internet connections for each locations have static IP addresses, but is there any way to get it working if one of the two internet connections for each location is a dynamic IP? Sorry for not including that fact on my original post.
0
 
LVL 1

Accepted Solution

by:
pcesolutions earned 500 total points
ID: 40175565
DMVPN
0
 

Author Comment

by:alex9420
ID: 40176014
Pcesolutions,
Look like it may work. I will check it out. Thank you.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Multiple Static IP addresses on Router 14 106
ASA Shunning internal IP 10 37
Tagging ports on a managed switch 6 52
Is WiFi half-duplex or Full -duplex 4 33
In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now