cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
401
Views
0
Helpful
3
Replies

VPN with hostnames and not IP addresses

johan.blom
Level 1
Level 1

Can the pix handel a VPN with hostnames as peers and not ip adresses. I want the pix to use DNS to go out and get the ip for the hostname because all sites except one uses dynamic ip's

3 Replies 3

mklaphek
Level 1
Level 1

I don't think it uses DNS resolution; I believe that it uses the hostname supplied by the initiating device

From the Cisco Docs:

"When two peers use IKE to establish IPSec security associations, each peer sends its ISAKMP identity to the remote peer. It will send either its IP address or host name depending on how each has its ISAKMP identity set. By default, the PIX Firewall unit's ISAKMP identity is set to the IP address. As a general rule, set the PIX Firewall and its peer's identities in the same way to avoid an IKE negotiation failure. This failure could be due to either the PIX Firewall or its peer not recognizing its peer's identity. "

Hope this helps.

The previous post is correct, the PIX will not use a DNS server to look up its peers IP address.

Thank you. Will this be changed in future releases? I know that dns is a unreiable structure so it can be a security problem yes. But what else could I use If I want to open a tunnel and both ip adresses are dynamical

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: