cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1491
Views
0
Helpful
8
Replies

Site to Site VPN with DDNS on remote FW

NMBowser
Level 1
Level 1

I have two sites right now: local site has an ASA 5505 and remote site has a Dray-Tek vigor 2133 series router with a ddns from dnsalias configured on it. My question is: Is it possible to configure our ASA to build a S2S tunnel using the Draytek's DDNS? I built a tunnel using ASDM but that does not allow a host name, only IP. The tunnel is currently build using the IP of the Draytek but the Ip on the DT side is changine more and more frequently. Any help would be greatly appreciated.

8 Replies 8

balaji.bandi
Hall of Fame
Hall of Fame

Never used Drayek VPN with ASA ( Draytek used for FW)

 

is ASA has static IP and Dreytek has Dynamic IP - not sure what option you use in draytek

 

check example :

 

https://blog.danmassey.net/cisco-asa-site-to-site-vpn-with-dynamic-ip-addresses/

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

The draytek has a ddns configured and the ASA has a static IP. I want to try to construct the tunnel using the DDNS so the Draytek side doesnt have to get a static IP. The Draytek side is working fine, I just can not find an option on the ASA side to build the tunnel using a ddns name rather than just an IP.

balaji.bandi
Hall of Fame
Hall of Fame

Why not Draytek initiate the Tunnel all time, since ASA has static IP. Like any EZY VPN style ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I would like to do this, but how would I configure the ASA to allow that?

In contrast to the IOS-router, there is no dynamic peer name resolution on the ASA for VPNs. As already mentioned, let the spoke initiate the connection and the ASA respond. Keep in mind that using wildcard PSKs is not a best practice and should be avoided. Using digital certificates is the way to go in this scenario.

Sorry for the n00b question, but how would I do that on the ASA side?

ASA-Draytek

under the ASA config dynamic map,

dynamic map don't need ip of other peer "other side of tunnel"

NOTE:-this config make only Draytek initiate traffic, ASA can not initiate the traffic.

ASA-Draytek

Other solution if this available in draytek , yes VTI in asa and use hostname as tunnel destination.

check this solution.