[nsp] Dynamic VPN & PIX

Voralt peder at voralt.net
Thu Aug 14 10:37:40 EDT 2003

Can you setup a lan to lan vpn between two pix's if each end is dynamic?

I know you can set some of the ISAKMP stuff as name instead of IP, but I
can't find a full sample config anywhere that shows what needs to be
changed.  For example, the pre-shared key line (isakmp key <key> address
<ip>) doesn't have a section for fqdn.  Do you just set it to all zero's and
use the "isakmp peer fqdn" line to tell it who can connect?

Also, what is the syntax to enter the name servers?  It doesn't start with
"dns", "name" or "ip".


