08-12-2008 11:37 PM - edited 02-21-2020 02:57 AM
hai friends,
i want to create site to site vpn between two sites but both the sites having dynamic ip.my question is ,is it possible to create site to site otherwise any other way is there ..if site to site is possible send any documentation
thanks
08-13-2008 04:08 AM
No you cannot make a site-2-site vpn with dynamic IPs on both sides. Dynamic crypto maps don't allow you to initiate connections, if both sides have dynamic crypto maps, who will initiate the connection?
You can setup a remote-access VPN. Preferably register the VPN server IP with dyn-dns. Then just enter the dyn-dns hostname of the VPN server in the Cisco VPN Client. Just make sure you are running a newer version of the Cisco VPN Client.
Regards
Farrukh
08-24-2008 10:37 PM
by register with ip dyn-dns we cant create site to site vpn .using hostname we can communicate ?...otherwise tell me possible way.
08-25-2008 04:32 AM
Yes it should work. Just make sure you use the latest version of the Cisco VPN Client.
Regards
Farrukh
08-25-2008 06:08 AM
thankyou for ur reply
i am not asking about remote vpn client...
it is possible to create site to site vpn using these dynamic dns hostname..
because i am having both sides dynamic ip.
if it is possible give me some example
thanks..
08-25-2008 06:20 AM
I already told you that you cannot. From my original response:
"No you cannot make a site-2-site vpn with dynamic IPs on both sides. Dynamic crypto maps don't allow you to initiate connections, if both sides have dynamic crypto maps, who will initiate the connection? "
Please rate if helpful.
Regards
Farrukh
08-25-2008 06:54 AM
thanks for ur reply..
so there is no solution...so only possibility is remote client
08-25-2008 07:00 AM
To my knowledge, YES.
Regards
Farrukh
08-25-2008 10:37 PM
hai
i configured remote client in asa 5505 and everything working fine.remotely connecting but the ip address and gateway is same..
for example i assign a pool 192.168.1.10-192.168.1.20
the ipconfig remotely
ip addrss 192.168.1.10
subnet 255.255.255.0
gateway 192.168.1.10...
so i am not able to access anything.
08-25-2008 11:33 PM
That default gateway is normal. Don't worry about that.
'acesss anything' what do you mean? Did you check the encr/decr on the ASA and the VPN client?
Regards
Farrukh
08-25-2008 11:40 PM
08-26-2008 04:10 AM
What is the point of defining a 'permit any' ACL and then doing a 'tunnelspecified'? Just do a "tunnelall".
Is phase 1 and 2 UP after the client connects? Do you see encap/decap?
show crypto ipsec sa
Regards
Farrukh
08-26-2008 05:36 AM
thanks
ok i ll do it
08-27-2008 09:25 AM
setup a DMVPN using NHRP at the hub site, which will keep track of the current global IP address at the two spokes, and they will be able to dynamically form tunnels between them, and even if the address changes, those updates will re-register with the NHRP server. That's assuming this is IOS-IOS VPN.
12-14-2010 11:39 AM
Have you tried using a dynamic update client on a computer inside each firewall and then building the VPN using FQDNs instead of the IP address.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide