I have a VPN setup to a destination that using ddns to keep the hostname across IP changes. This works fine as long as the remote end is initiating the tunnel, but it seems the PA cannot be configured to be able to also *initiate* the tunnel:
When the remote IKE Gateway is configured to "Peer Type: Static" I could enter an IP address, but since the destination has a dynamic IP this is not an option.
When the remote IKE Gateway is configured to "Peer Type: Dynamic" I cannot enter anything (like hostname) anymore, so obviously the PA does not have sufficient information to establish the tunnel although it should be technically possible with Agressive Mode.
(Note that the configurable "Peer Identification FQDN" that can be entered in is only for identification purpose and will of course not be used to connect to the destination)
Is this a known limitation? Any Feature Requests pending for this?
Did you ever determine a solution as I am in the same boat right now. I have a remote CradlePoint router connecting back to my 3020. The CradlePoint has dual-isps and I would love to use just a name on the 3020 end and have the tunnel flip if ISP1 goes down.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!