Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN with dynamic IPs?

Status
Not open for further replies.

jneiberger

Technical User
Jan 21, 2005
1,791
US
I'm only lightly familiar with the ASA, so I don't know if this is even possible. Here's what we'd like to do:

We have some mobile laptops with Sprint cards as well as wifi cards. These laptops would have a Cisco VPN client installed. We want them to be able to use the VPN when their in Sprint coverage areas, but they also need to be able to use it when they pull into certain wifi hotspots we have created for them throughout our city.

Their IP address will change when the switch networks, so I'm sure that would break the VPN. One option is to have the user disconnect and reconnect every time they move in and out of these zones, but we'd rather find a way for it to happen dynamically. These are emergency service workers and they have enough on their minds without having to deal with our VPN issues. We want to make it transparent to them, if possible.

Is there a way to make the tunnel dynamically reconnect every time the laptop grabs a new IP address?
 
Hmmm, I'm not aware of any way to do this. Say they connect from their Sprint card (using 66.99.101.12 as the IP) to the VPN. The firewall will build a tunnel from 66.99.101.12. If they relocate to another area and get a different IP address, the tunnel will need to be rebuilt using the new IP.

Perhaps SuperG knows a way, we'll need to wait for him to reply.

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
You've got it exactly right. I'm hoping to find some way to make that dynamic. Otherwise, the users will have to manually disconnect and reconnect every time they move between coverage areas. Or, we'd have to find an automated way to reconnect them.

I was wondering if maybe there was a way to trigger a batch file based on the state of the wifi connection. Every time it changes, run the batch file to stop and restart the VPN. I have no idea if that's possible or not.
 
There may be a way to do this, but you'll need to enlist the help of the professionals in the VBScript forum. They can do anything I swear lol. Good luck.

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top