[Contents] [Prev] [Next] [Index] [Report an Error]

Configuring Dynamic Endpoints

IPSec tunnels can also be established using dynamic peer security gateways, in which the remote end of the tunnels do not have a statically assigned IP address. Since the remote address is not known and might be pulled from an address pool each time the remote host reboots, establishment of the tunnel relies on using IKE main mode with either preshared global keys or digital certificates that accept any remote identification value. For more information on IKE policy modes, see Configuring the IKE Policy Mode. Both policy-based and link-type tunnels are supported:

This section includes the following topics:


[Contents] [Prev] [Next] [Index] [Report an Error]