VPN to dynamic (ddns) destination

Reply
Highlighted
L1 Bithead

VPN to dynamic (ddns) destination

I have a VPN setup to a destination that using ddns to keep the hostname across IP changes. This works fine as long as the remote end is initiating the tunnel, but it seems the PA cannot be configured to be able to also *initiate* the tunnel:

When the remote IKE Gateway is configured to "Peer Type: Static" I could enter an IP address, but since the destination has a dynamic IP this is not an option.

When the remote IKE Gateway is configured to "Peer Type: Dynamic" I cannot enter anything (like hostname) anymore, so obviously the PA does not have sufficient information to establish the tunnel although it should be technically possible with Agressive Mode.

(Note that the configurable "Peer Identification FQDN" that can be entered in is only for identification purpose and will of course not be used to connect to the destination)

Is this a known limitation? Any Feature Requests pending for this?

Thanks,

   Christian

Highlighted
L3 Networker

Re: VPN to dynamic (ddns) destination

Did you ever determine a solution as I am in the same boat right now.  I have a remote CradlePoint router connecting back to my 3020.  The CradlePoint has dual-isps and I would love to use just a name on the 3020 end and have the tunnel flip if ISP1 goes down.

Highlighted
L1 Bithead

Re: VPN to dynamic (ddns) destination

Unfortunately no

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!