cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1064
Views
0
Helpful
2
Replies

ASA VPN Tunnels with Certificates

Hi there,

I'm newbie in the CISCO supportforum and have a question about VPN Tunnels between ASA's.

My ASA's have the follwing Versions: ASA Version 8.4(3) ASDM Version 6.4(7)

Have I a chance  to configure a site-to-site tunnel with a hostname as peer address when I will use Identity and CA Certificates?

Is there a How-To or more  information in the supportforum?

Many Thanks for replies

Rainer Bolsinger

2 Replies 2

mwinnett
Level 3
Level 3

There is a detailed config example at

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080aa5be1.shtml

However, this use ip-address rather than hostname.  I don't see any reason why you cannot use hostname instead. You would have to try (Unless anyone else knows better).

Matthew

If you want to use FQDNs because both your ASAs have dynamic IP-addresses, then the answer is no. At least one ASA needs to have a fixed IP. And then it doest't matter if you use PSK or certificate-authentication. But the IPSec peer always has to be specified by the IP-address.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni