//Interfaces
pawel.klimko@ERL01-Bydgoszcz-Gajowa-PL# show interfaces vti vti vti1 { address 10.10.254.2/30 description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-HUB-DE1" firewall { in { name VTI_IN_OCTOPUS } } mtu 1436 } vti vti6 { address 10.0.80.34/30 description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-HUB-UK1" firewall { in { name VTI_IN_OTHER } } ip { ospf { authentication { md5 { key-id 1 { md5-key ***** } } } dead-interval 40 hello-interval 10 priority 1 retransmit-interval 5 transmit-delay 1 } } mtu 1436 }
//VPN
vpn { ipsec { auto-firewall-nat-exclude disable esp-group ESP-VYOS { compression disable lifetime 1800 mode tunnel pfs enable proposal 1 { encryption aes256 hash sha512 } proposal 2 { encryption 3des hash md5 } } ike-group IKE-VYOS { dead-peer-detection { action restart interval 30 timeout 120 } ikev2-reauth no key-exchange ikev1 lifetime 3600 proposal 1 { dh-group 2 encryption aes256 hash sha512 } proposal 2 { dh-group 2 encryption aes256 hash sha512 } } ipsec-interfaces { interface eth0 } site-to-site { peer 88.208.192.*** { authentication { mode pre-shared-secret pre-shared-secret krasnal } connection-type respond default-esp-group ESP-VYOS description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-HUB-UK1" ike-group IKE-VYOS ikev2-reauth inherit local-address 89.65.204.*** vti { bind vti6 esp-group ESP-VYOS } } peer 94.177.226.*** { authentication { mode pre-shared-secret pre-shared-secret krasnal@87 } connection-type respond default-esp-group ESP-VYOS description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-HUB-DE1" ike-group IKE-VYOS ikev2-reauth inherit local-address 89.65.204.** vti { bind vti1 esp-group ESP-VYOS } } } }
PUBLIC IP ON WAN
ERL01-Bydgoszcz-Gajowa-PL
89.65.204.**
vYos-VPN-HUB-UK1
88.208.192.***
vYos-VPN-HUB-DE1
94.177.226.***
I want change address in peer to domain name:
ERL01-Bydgoszcz-Gajowa-PL.domain.com
vYos-VPN-HUB-UK1.domain.com
vYos-VPN-HUB-DE1.domain.com
I have configured subdomain but i don't know what i must change in configuration. When i use this command i have error:
set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com authentication mode pre-shared-secret set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com authentication pre-shared-secret krasnal@87 set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com connection-type respond set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com default-esp-group ESP-VYOS set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-CLIENT1" set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com ike-group IKE-VYOS set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com local-address any set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com vti bind vti2 set vpn ipsec site-to-site peerERL01-Bydgoszcz-Gajowa-PL.domain.com vti esp-group ESP-VYOS
COMMIT ERROR:
[ vpn ] Error: an IP address is expected rather than "ERL01-Bydgoszcz-Gajowa-PL.domain.com" Cannot find device "vti1" Cannot find device "vti1" Error: an IP address is expected rather than "vyos-vpn-hub-de1.domain.com" Cannot find device "vti2" Cannot find device "vti2" _errloc_:[ vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com vti ] VPN configuration error: No mark specified for peer "ERL01-Bydgoszcz-Gajowa-PL.domain.com" vti
Pleas Help Me How i can connect router A with router B via VPN uses public domain ?