<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN to dynamic (ddns) destination in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-to-dynamic-ddns-destination/m-p/3400#M2531</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a VPN setup to a destination that using ddns to keep the hostname across IP changes. This works fine as long as the remote end is initiating the tunnel, but it seems the PA cannot be configured to be able to also *initiate* the tunnel:&lt;/P&gt;&lt;P&gt;When the remote IKE Gateway is configured to "Peer Type: Static" I could enter an IP address, but since the destination has a dynamic IP this is not an option.&lt;/P&gt;&lt;P&gt;When the remote IKE Gateway is configured to "Peer Type: Dynamic" I cannot enter anything (like hostname) anymore, so obviously the PA does not have sufficient information to establish the tunnel although it should be technically possible with Agressive Mode.&lt;/P&gt;&lt;P&gt;(Note that the configurable "Peer Identification FQDN" that can be entered in is only for identification purpose and will of course not be used to connect to the destination)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a known limitation? Any Feature Requests pending for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jun 2012 18:37:55 GMT</pubDate>
    <dc:creator>ctr_ts</dc:creator>
    <dc:date>2012-06-26T18:37:55Z</dc:date>
    <item>
      <title>VPN to dynamic (ddns) destination</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-to-dynamic-ddns-destination/m-p/3400#M2531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a VPN setup to a destination that using ddns to keep the hostname across IP changes. This works fine as long as the remote end is initiating the tunnel, but it seems the PA cannot be configured to be able to also *initiate* the tunnel:&lt;/P&gt;&lt;P&gt;When the remote IKE Gateway is configured to "Peer Type: Static" I could enter an IP address, but since the destination has a dynamic IP this is not an option.&lt;/P&gt;&lt;P&gt;When the remote IKE Gateway is configured to "Peer Type: Dynamic" I cannot enter anything (like hostname) anymore, so obviously the PA does not have sufficient information to establish the tunnel although it should be technically possible with Agressive Mode.&lt;/P&gt;&lt;P&gt;(Note that the configurable "Peer Identification FQDN" that can be entered in is only for identification purpose and will of course not be used to connect to the destination)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a known limitation? Any Feature Requests pending for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 18:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-to-dynamic-ddns-destination/m-p/3400#M2531</guid>
      <dc:creator>ctr_ts</dc:creator>
      <dc:date>2012-06-26T18:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN to dynamic (ddns) destination</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-to-dynamic-ddns-destination/m-p/3401#M2532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you ever determine a solution as I am in the same boat right now.&amp;nbsp; I have a remote CradlePoint router connecting back to my 3020.&amp;nbsp; The CradlePoint has dual-isps and I would love to use just a name on the 3020 end and have the tunnel flip if ISP1 goes down.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 15:36:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-to-dynamic-ddns-destination/m-p/3401#M2532</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-10-03T15:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN to dynamic (ddns) destination</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-to-dynamic-ddns-destination/m-p/3402#M2533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately no&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Feb 2014 16:15:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-to-dynamic-ddns-destination/m-p/3402#M2533</guid>
      <dc:creator>ctr_ts</dc:creator>
      <dc:date>2014-02-04T16:15:56Z</dc:date>
    </item>
  </channel>
</rss>

