[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: isakmpd: unknown id type user_fqdn



Hakan Olsson schrob:
 
> One could argue that isakmpd should automatically translate a FQDN to an
> address for a Phase 2 ID, but this is currently not done. I don't really
> see a good reason why we should either.

Well, it would still be ID-type IPV{4,6}_ADDR then, right? But I think, 
especially in a road-warrior-type scenario (with isakmpd running on 
the road-warrior-box) it would make sense to be able to specify a hostname 
in an "Address" tag. After all, dynamic IP-addresses are very common in
this kind of scenario. In Phase 1 you can leave out "Local-Address",
so dynamic IPs are not a problem, if I remember correctly. 

But how do you specify Local-ID in a road-warrior (host-to-net) setup? I 
have not tried yet, but I think you cannot just leave it out. And 
rewriting isakmpd.conf on every address change isn't exactly elegant 
either.

ciaole
schmadde