Setting up Site to site VPN when one side has a dynamic IP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Setting up Site to site VPN when one side has a dynamic IP

L3 Networker

Hi ,

You can use the Easy VPN setup in Cisco ASA to create a site to site VPN from a remote site that does not have a static IP address associated with it. Is it possible to do the same when the Main Office device is a Palo Alto firewall ?

The remote office device will be a Cisco ASA configured to initiate a IPSEC connection to the corporate Palo Alto device. But I need Palo to be configured to accept the IPSEC connection irrespective of the source IP from which the ASA initiates the connection. Is this possible ?

If so , could you briefly describe how it is done ?

Regards,

Sunil

1 accepted solution

Accepted Solutions

Retired Member
Not applicable

Yes this is possible. On PA side you would need to be able to identify the peer by means other than IP. That usually means FQDN. So Cisco should send local ID as FQDN (i.e. vpn.domain.com). PA side should have same for peer ID. You will also need to have both sides in aggressive mode as well (default is main mode). Otherwise other parameters such as P1 and P2 proposals, preshared keys, proxy-ids, etc. are pretty much same.

Note that in this case the Cisco must always be initiator of the VPN.

-Richard

View solution in original post

3 REPLIES 3

Retired Member
Not applicable

Yes this is possible. On PA side you would need to be able to identify the peer by means other than IP. That usually means FQDN. So Cisco should send local ID as FQDN (i.e. vpn.domain.com). PA side should have same for peer ID. You will also need to have both sides in aggressive mode as well (default is main mode). Otherwise other parameters such as P1 and P2 proposals, preshared keys, proxy-ids, etc. are pretty much same.

Note that in this case the Cisco must always be initiator of the VPN.

-Richard

Thanks Richard,

I will try it and confirm if it works.

So....did it work?

  • 1 accepted solution
  • 4173 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!