Quantcast
Viewing all articles
Browse latest Browse all 20028

VPN site-to-site ipsec use Hostname in peer name ?

//Interfaces

pawel.klimko@ERL01-Bydgoszcz-Gajowa-PL# show interfaces vti 
 vti vti1 {
     address 10.10.254.2/30
     description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-HUB-DE1"
     firewall {
         in {
             name VTI_IN_OCTOPUS
         }
     }
     mtu 1436
 }
 vti vti6 {
     address 10.0.80.34/30
     description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-HUB-UK1"
     firewall {
         in {
             name VTI_IN_OTHER
         }
     }
     ip {
         ospf {
             authentication {
                 md5 {
                     key-id 1 {
                         md5-key *****
                     }
                 }
             }
             dead-interval 40
             hello-interval 10
             priority 1
             retransmit-interval 5
             transmit-delay 1
         }
     }
     mtu 1436
 }

 

//VPN

 

vpn {
     ipsec {
         auto-firewall-nat-exclude disable
         esp-group ESP-VYOS {
             compression disable
             lifetime 1800
             mode tunnel
             pfs enable
             proposal 1 {
                 encryption aes256
                 hash sha512
             }
             proposal 2 {
                 encryption 3des
                 hash md5
             }
         }
         ike-group IKE-VYOS {
             dead-peer-detection {
                 action restart
                 interval 30
                 timeout 120
             }
             ikev2-reauth no
             key-exchange ikev1
             lifetime 3600
             proposal 1 {
                 dh-group 2
                 encryption aes256
                 hash sha512
             }
             proposal 2 {
                 dh-group 2
                 encryption aes256
                 hash sha512
             }
         }
         ipsec-interfaces {
             interface eth0
         }
         site-to-site {
             peer 88.208.192.*** {
                 authentication {
                     mode pre-shared-secret
                     pre-shared-secret krasnal
                 }
                 connection-type respond
                 default-esp-group ESP-VYOS
                 description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-HUB-UK1"
                 ike-group IKE-VYOS
                 ikev2-reauth inherit
                 local-address 89.65.204.***
                 vti {
                     bind vti6
                     esp-group ESP-VYOS
                 }
             }
             peer 94.177.226.*** {
                 authentication {
                     mode pre-shared-secret
                     pre-shared-secret krasnal@87
                 }
                 connection-type respond
                 default-esp-group ESP-VYOS
                 description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-HUB-DE1"
                 ike-group IKE-VYOS
                 ikev2-reauth inherit
                 local-address 89.65.204.**
                 vti {
                     bind vti1
                     esp-group ESP-VYOS
                 }
             }
         }
     }

 

PUBLIC IP ON WAN

 

ERL01-Bydgoszcz-Gajowa-PL

89.65.204.**

 

vYos-VPN-HUB-UK1

88.208.192.***

 

vYos-VPN-HUB-DE1

94.177.226.***

 

I want change address in peer to domain name:

ERL01-Bydgoszcz-Gajowa-PL.domain.com

vYos-VPN-HUB-UK1.domain.com

vYos-VPN-HUB-DE1.domain.com

 

I have configured subdomain but i don't know what i must change in configuration. When i use this command i have error:

 

 

set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com authentication mode pre-shared-secret
set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com authentication pre-shared-secret krasnal@87
set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com connection-type respond
set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com default-esp-group ESP-VYOS
set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com description "ERL01-Bydgoszcz-Gajowa-PL -> vYos-VPN-CLIENT1"
set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com ike-group IKE-VYOS
set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com local-address any
set vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com vti bind vti2
set vpn ipsec site-to-site peerERL01-Bydgoszcz-Gajowa-PL.domain.com vti esp-group ESP-VYOS

 

COMMIT ERROR:

[ vpn ]
Error: an IP address is expected rather than "ERL01-Bydgoszcz-Gajowa-PL.domain.com"
Cannot find device "vti1"
Cannot find device "vti1"
Error: an IP address is expected rather than "vyos-vpn-hub-de1.domain.com"
Cannot find device "vti2"
Cannot find device "vti2"
_errloc_:[ vpn ipsec site-to-site peer ERL01-Bydgoszcz-Gajowa-PL.domain.com vti ]
VPN configuration error: No mark specified for peer "ERL01-Bydgoszcz-Gajowa-PL.domain.com" vti

Pleas Help Me How i can connect router A with router B via VPN uses public domain ?


Viewing all articles
Browse latest Browse all 20028

Trending Articles