04-02-2003 01:14 AM - edited 02-21-2020 12:27 PM
Can the pix handel a VPN with hostnames as peers and not ip adresses. I want the pix to use DNS to go out and get the ip for the hostname because all sites except one uses dynamic ip's
04-02-2003 01:26 PM
I don't think it uses DNS resolution; I believe that it uses the hostname supplied by the initiating device
From the Cisco Docs:
"When two peers use IKE to establish IPSec security associations, each peer sends its ISAKMP identity to the remote peer. It will send either its IP address or host name depending on how each has its ISAKMP identity set. By default, the PIX Firewall unit's ISAKMP identity is set to the IP address. As a general rule, set the PIX Firewall and its peer's identities in the same way to avoid an IKE negotiation failure. This failure could be due to either the PIX Firewall or its peer not recognizing its peer's identity. "
Hope this helps.
04-02-2003 05:38 PM
The previous post is correct, the PIX will not use a DNS server to look up its peers IP address.
04-02-2003 10:51 PM
Thank you. Will this be changed in future releases? I know that dns is a unreiable structure so it can be a security problem yes. But what else could I use If I want to open a tunnel and both ip adresses are dynamical
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: