Koozali.org: home of the SME Server
Legacy Forums => Experienced User Forum => Topic started by: philippe peltier on November 26, 2003, 11:22:12 AM
-
Hello,
I have a question..
Is it possible with freeswan (or another one) to set up an ipsec vpn beetween two sites using dynamic dns ?
I'd be very interested in knowing...
tnx in advance.
-
Hi Philippe,
>Is it possible with freeswan (or another one) to set up an ipsec vpn
>beetween two sites using dynamic dns ?
Yes.
Kelvin
-
Kelvin wrote:
>
> Hi Philippe,
>
> >Is it possible with freeswan (or another one) to set up an
> ipsec vpn
> >beetween two sites using dynamic dns ?
>
> Yes.
>
> Kelvin
May I ask : how ?
Phil.
-
Kevin would answer (I guess)
>
> May I ask : how?
>
Yes, you may (ask).
:-)
-
It is given in the freeswan how-to. The current freeswan contrib at contribs.org will allow the use of IP address or dns name (dynamic or otherwise) to refer to the end points.
Kelvin
-
and Can I ask how to setup a IPSEC VPN?
:)
TIA
-
>and Can I ask how to setup a IPSEC VPN?
>:)
And I would answer in short "Follow the freeswan howto at contribs.org" :)
Kelvin
-
Kelvin wrote:
>
> >and Can I ask how to setup a IPSEC VPN?
> >:)
>
> And I would answer in short "Follow the freeswan howto at
> contribs.org" :)
>
> Kelvin
And I'd Ask "Ok, I put 'www.mydynamicdomain.com' in the 'Remote Router's External IP Address:' , but WTF do I put in 'Remote Router's External Gateway IP' "??? ;-)
Although my freeswan and howto (dmc-mitel-freeswan-1.97-3sme55.noarch.rpm)come from contrib.org, there is not a word in the howto about dynamic DNSes...
Phil.
-
Hi Phillipe,
I skipped SME 5.5 and anything to to with it altogether, so I am unfamiliar with your version of the freeswan howto.
The Freeswan Howto I use is the one from Shad Lords. While the freeswan how-to does not explicitly mention dynamic IP addresses, you will find that it mentions that you can use either a dns (or hostname) or an IP address for the remote address which means, you can use dynamic IPs (if you update your IP with a dynamic DNS provider) with that contrib.
Shad's howto does not require you to enter the remote gateway address either.
Kelvin