×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

ASA VPN Tunnels with Certificates

Unanswered Question
Aug 17th, 2012
User Badges:

Hi there,


I'm newbie in the CISCO supportforum and have a question about VPN Tunnels between ASA's.

My ASA's have the follwing Versions: ASA Version 8.4(3) ASDM Version 6.4(7)


Have I a chance  to configure a site-to-site tunnel with a hostname as peer address when I will use Identity and CA Certificates?

Is there a How-To or more  information in the supportforum?


Many Thanks for replies

Rainer Bolsinger

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Karsten Iwen Fri, 08/24/2012 - 00:58
User Badges:
  • Purple, 4500 points or more
  • Cisco Designated VIP,

    2017 Firewalling, VPN

If you want to use FQDNs because both your ASAs have dynamic IP-addresses, then the answer is no. At least one ASA needs to have a fixed IP. And then it doest't matter if you use PSK or certificate-authentication. But the IPSec peer always has to be specified by the IP-address.



-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Actions

This Discussion