Problems using IPSEC Dinamic IPs and DDNS

Unanswered Question
Jul 12th, 2007
User Badges:


I am trying to set up VPN GW-GW between C857 and C877. One of the sites has fixed IP, but the other one has dinamic IP assigned by ISP. If I use IPs when setting up ipsec tunnel with preshared keys, I find no problems, but if I use hostname for one of the sites, taking advantage of Dynamic DNS, vpn cant be established, with an error of key missmatch in the side where I use hostname.

I configure hostname in:

crypto isakmp key "key" hostname "hostnme"

Cryptomap: set peer "hostname"

Do I have to use for this situation with dynamic IPs certificates?

Can anyone help?

Thanks in advance

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
ggilbert Thu, 07/12/2007 - 08:59
User Badges:
  • Cisco Employee,


You have to use "address" for this. IF you are trying to do it by DDNS, you have to use certificates.

Configure a CA server and you should be able to get this working with the Certificates.

Rate this post, if it helps.




This Discussion