[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: isakmpd: unknown id type user_fqdn
Hakan Olsson schrob:
> One could argue that isakmpd should automatically translate a FQDN to an
> address for a Phase 2 ID, but this is currently not done. I don't really
> see a good reason why we should either.
Well, it would still be ID-type IPV{4,6}_ADDR then, right? But I think,
especially in a road-warrior-type scenario (with isakmpd running on
the road-warrior-box) it would make sense to be able to specify a hostname
in an "Address" tag. After all, dynamic IP-addresses are very common in
this kind of scenario. In Phase 1 you can leave out "Local-Address",
so dynamic IPs are not a problem, if I remember correctly.
But how do you specify Local-ID in a road-warrior (host-to-net) setup? I
have not tried yet, but I think you cannot just leave it out. And
rewriting isakmpd.conf on every address change isn't exactly elegant
either.
ciaole
schmadde