cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
688
Views
0
Helpful
3
Replies

ASA IPSEC VPN with dynamic public IP

m1xed0s
Spotlight
Spotlight

Hey,

I never deployed production IPSEC VPN tunnel using ASA on both sides with one side using dynamic public IP. I normally deploy VPN Tunnels with both sides using static public IP addresses (not always has public IP on ASA directly though).

So I am wonder how stable it works with one side static public IP and the other side uses dynamic public IP?

Thanks,

Shuai                  

1 Accepted Solution

Accepted Solutions

martinbuffleo
Level 1
Level 1

If you use certificates and main mode, or psk and aggressive it will work fine. I have a number of production sites using this method.

Sent from Cisco Technical Support iPad App

View solution in original post

3 Replies 3

martinbuffleo
Level 1
Level 1

If you use certificates and main mode, or psk and aggressive it will work fine. I have a number of production sites using this method.

Sent from Cisco Technical Support iPad App

So you mean using certificates and main mode OR psk and aggressive mode on the side using dynamic public IP, right?

I might build one in lab and stress test it.

Yep. Dynamic tunnels don't work in main mode with pre shared keys

Sent from Cisco Technical Support iPad App