Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Site to Site VPN Cisco 877

Status
Not open for further replies.

ifconf

IS-IT--Management
Nov 15, 2004
28
0
0
GB
I have R62 running on an IP390 cluster. I need to setup a VPN with a Cisco 877 router which has a dynamically assigned IP address from the ISP. Does anyone know if this is possible and if so help me with some tips, also where can I find documentation on this subject CP site doesn't seem to have anything.

Many thanks
 
This can be done, but since you are going to be setting this VPN tunnel with a Cisco device that has a dynamic IP address you'll need to use certificates for authentication (pre-shared secrets cannot be used)

You can refer to the VPN Admin Guide from Checkpoint's website for details on setting this up. But this will be basically by defining an interoperable device, choosing "dynamic IP" and configuring the certificates.

I would advise that you use the Checkpoint CA for issuing a certificate to the Cisco device as this will be much easier than setting another 3rd party CA.

 
Is it because its a Cisco 877 that is does not support psk or because it a dynamically assigned address? I build tunnels all the time to dynamic IP's using psk and haven never ran into any issues.

IT Security news and information
In plain English
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top