08-17-2012 10:26 AM
Hi there,
I'm newbie in the CISCO supportforum and have a question about VPN Tunnels between ASA's.
My ASA's have the follwing Versions: ASA Version 8.4(3) ASDM Version 6.4(7)
Have I a chance to configure a site-to-site tunnel with a hostname as peer address when I will use Identity and CA Certificates?
Is there a How-To or more information in the supportforum?
Many Thanks for replies
Rainer Bolsinger
08-24-2012 12:43 AM
There is a detailed config example at
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080aa5be1.shtml
However, this use ip-address rather than hostname. I don't see any reason why you cannot use hostname instead. You would have to try (Unless anyone else knows better).
Matthew
08-24-2012 12:58 AM
If you want to use FQDNs because both your ASAs have dynamic IP-addresses, then the answer is no. At least one ASA needs to have a fixed IP. And then it doest't matter if you use PSK or certificate-authentication. But the IPSec peer always has to be specified by the IP-address.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide