03-26-2014 05:29 AM
Hi all,
I have some ASA Site-to-Site (L2L ikev2) VPN deployments that are using A Dyanic-to-Static Peer configuration. Now I have a special case where I cannot get a static IP for either end and have been researching for a solution to connect L2L with Dynamic-to-Dynamic peers. My research is not really turning up anything and now I am thinking that the ASA may not be capable of this configuration. Can anyone confirm that this is or is not possible?
My hardware is ASA 5505 running 9.1.4.
Thanks!
Shelby
03-27-2014 11:12 AM
Are you talking about using some sort of dyndns?
How would the two devices find each other?
03-27-2014 03:45 PM
This will not be possible. You will need at least one static IP address so that at least one end of the tunnel can be configured with an IP address to connect back to. If they are both dynamic then you have no way to tell either ASA where the far end of the tunnel is located.
Hope that helps.
03-28-2014 12:30 AM
As already mentioned, you can't do that with the ASA. But with IOS-routers there are two possible ways to achieve that:
03-28-2014 06:45 AM
Thanks all. I was searching for a solution using FQDN, but only have ASA as a choice. Just wanted to be sure that this was not possible on ASA prior to seeking alternate solution and hardware.
Thanks again for the confirmation!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: