cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Who Me Too'd this topic

VPN to dynamic (ddns) destination

L1 Bithead

I have a VPN setup to a destination that using ddns to keep the hostname across IP changes. This works fine as long as the remote end is initiating the tunnel, but it seems the PA cannot be configured to be able to also *initiate* the tunnel:

When the remote IKE Gateway is configured to "Peer Type: Static" I could enter an IP address, but since the destination has a dynamic IP this is not an option.

When the remote IKE Gateway is configured to "Peer Type: Dynamic" I cannot enter anything (like hostname) anymore, so obviously the PA does not have sufficient information to establish the tunnel although it should be technically possible with Agressive Mode.

(Note that the configurable "Peer Identification FQDN" that can be entered in is only for identification purpose and will of course not be used to connect to the destination)

Is this a known limitation? Any Feature Requests pending for this?

Thanks,

   Christian

Who Me Too'd this topic