cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
976
Views
0
Helpful
2
Replies

ASA VPN Tunnels with Certificates

Hi there,

I'm newbie in the CISCO supportforum and have a question about VPN Tunnels between ASA's.

My ASA's have the follwing Versions: ASA Version 8.4(3) ASDM Version 6.4(7)

Have I a chance  to configure a site-to-site tunnel with a hostname as peer address when I will use Identity and CA Certificates?

Is there a How-To or more  information in the supportforum?

Many Thanks for replies

Rainer Bolsinger

2 Replies 2

mwinnett
Level 3
Level 3

There is a detailed config example at

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080aa5be1.shtml

However, this use ip-address rather than hostname.  I don't see any reason why you cannot use hostname instead. You would have to try (Unless anyone else knows better).

Matthew

If you want to use FQDNs because both your ASAs have dynamic IP-addresses, then the answer is no. At least one ASA needs to have a fixed IP. And then it doest't matter if you use PSK or certificate-authentication. But the IPSec peer always has to be specified by the IP-address.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: