Re: Cisco PIX issue with isakmp identity of peer
"John Spanos" <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <[email protected]> |
Hi all, I have a problem I am trying to figure out. I have a PIX at head office with various other IPSec peers connected via permanent tunnels. I also have a remote client based VPN that uses certificates on the same PIX. Now, for the certificate-based client VPN to operate I MUST have the isakmp identity hostname command set. All my existing site-to-site VPN operate fine under this scenario but I am trying to add a new VPN to a Billion ADSL Firewall which fails under this situation. I run debug output and found that the PIX was doing an ID_FQDN check of the isakmp peer and failing. If I then change the isakmp identity command to address I can successfully setup the tunnel but then my client based VPN is cactus! If anyone can shed some light on getting around this issue I'd much appreciate it. I am not sure HOW the PIX checks the FQDN as I can't find anywhere in configuration documents on how to force the PIX to check a particular DNS Server. Or does it check against 'names' configured hosts in its own config. Thanks In Advance. John Spanos.