Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX - Site2Site - Dynamic IP - Changes

Status
Not open for further replies.

maynarja

MIS
Jan 24, 2007
41
CA
Site to Site using PIX and pfSense

pfSense is dynamic and intiates the VPN
PIX is Static

pfSense ------- INTERNET ------- PIX

If pfeSense's IP changes the tunnel is dropped which is expected but pfSense cannot connect without a reboot. PIX sees the attempt but blocks it with an ACL.

I assume that pfSense is sending the SA with a changed IP and the PIX identifies that as an attempt to spoof the tunnel.

Is there anything I can do on the PIX side or do I have to reduce the SA's lifetime to minutes and what consequence would that be... much more traffic and.....
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top