cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
887
Views
0
Helpful
2
Replies

Real-Time Resolution for IPSec Tunnel Peer

remi-reszka
Level 1
Level 1

Hi,

There is a document on Cisco website

http://www.cisco.com/en/US/docs/ios/12_3t/12_3t4/feature/guide/gtrlres.html

explaining that while configuring a static crypto map and peers instead of peer IP address we can specify a FQDN following with "dynamic" command. I have been trying this option and no luck. My VPN endpoint (routers 2611XM and 831) do resolve each other name with a DNS server but when it's coming to apllying crypto maps to the interfaces I get the following error message:

ISAKMP: callback: no SA found for 0.0.0.0/0.0.0.0 [vrf 0]

So to speak no SAs are being established and IPSec tunnel failes to come up.

Anybody tried that and had the same problem? I'd appreciate your help on that.

Thanks,

Remi

1 Accepted Solution

Accepted Solutions

ovt
Level 4
Level 4

What authentication method do you use? If you use "pre-share" you still cannot use "cry isa key ... name ..." even if the DNS resolves this to an IP address. This is a feature of the IKE MM. So, use certs instead.

View solution in original post

2 Replies 2

ovt
Level 4
Level 4

What authentication method do you use? If you use "pre-share" you still cannot use "cry isa key ... name ..." even if the DNS resolves this to an IP address. This is a feature of the IKE MM. So, use certs instead.

Exactly, I was using pre-share key authentication. I am in process of deploying certs to see how it's gonna work.

Thanks for your help.

Remi