cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
884
Views
0
Helpful
2
Replies

Real-Time Resolution for IPSec Tunnel Peer

remi-reszka
Level 1
Level 1

Hi,

There is a document on Cisco website

http://www.cisco.com/en/US/docs/ios/12_3t/12_3t4/feature/guide/gtrlres.html

explaining that while configuring a static crypto map and peers instead of peer IP address we can specify a FQDN following with "dynamic" command. I have been trying this option and no luck. My VPN endpoint (routers 2611XM and 831) do resolve each other name with a DNS server but when it's coming to apllying crypto maps to the interfaces I get the following error message:

ISAKMP: callback: no SA found for 0.0.0.0/0.0.0.0 [vrf 0]

So to speak no SAs are being established and IPSec tunnel failes to come up.

Anybody tried that and had the same problem? I'd appreciate your help on that.

Thanks,

Remi

1 Accepted Solution

Accepted Solutions

ovt
Level 4
Level 4

What authentication method do you use? If you use "pre-share" you still cannot use "cry isa key ... name ..." even if the DNS resolves this to an IP address. This is a feature of the IKE MM. So, use certs instead.

View solution in original post

2 Replies 2

ovt
Level 4
Level 4

What authentication method do you use? If you use "pre-share" you still cannot use "cry isa key ... name ..." even if the DNS resolves this to an IP address. This is a feature of the IKE MM. So, use certs instead.

Exactly, I was using pre-share key authentication. I am in process of deploying certs to see how it's gonna work.

Thanks for your help.

Remi

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: