Cisco Systems ezvpn w/ router which has changing public address (PPPoE)

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
ezvpn w/ router which has changing public address (PPPoE) =?ISO-8859-15?Q?J=F6rg_Sch=FCt 03-05-06
Posted by =?ISO-8859-15?Q?J=F6rg_Sch=FCt on March 5, 2006, 4:18 am
Please log in for more thread options
Hi

We want to set up a VPN connection between our ASA 55xx and a
router (Cisco 1841) which will get it's public IP via PPPoE.
When using PPPoE we will not know which will be our IP address
(it will change every 24 hours).
We are not able to establish a vpn connection (not even phase 1)
between these two devices.
There was no problem establishing a vpn connection when this
router had a fixed ip address by routing all the traffic to the
default gateway of the ISP. The ASA had no knowledge about the
fixed IP of the router.
To make things more complicated, we have no real dynamic address
assignment from our ISP. We have to set the IP address manually to
establish a connection via PPPoE.
Can anyone plese point out where the error in this config is?

version 12.4
hostname yourname
no aaa new-model
ip subnet-zero
no ip cef
no ip dhcp use vrf connected
ip dhcp pool test
   network 10.250.7.8 255.255.255.248
   dns-server 192.168.1.1
   default-router 10.250.7.9
   lease infinite
!
no ip domain lookup
vpdn enable
!
username xyzxyz password 0 asdfasdfasdf
!
crypto isakmp policy 1
 encr aes
 authentication pre-share
 group 2
crypto isakmp keepalive 20
!
crypto ipsec transform-set Strong esp-aes esp-sha-hmac
!
crypto ipsec client ezvpn nameOfTunnelGroup
 connect auto
 group dynVPN key jkljkljkljlk
 local-address FastEthernet0/1
 mode network-extension
 peer 1.2.3.4
 username xyzxyz password asdfasdfasdf
 xauth userid mode local
!
!
interface FastEthernet0/0
 description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-FE 0$
 ip address 10.250.7.9 255.255.255.248
 ip virtual-reassembly
 ip tcp adjust-mss 1452
 duplex auto
 speed auto
 no cdp enable
 crypto ipsec client ezvpn nameOfTunnelGroup inside
!
interface FastEthernet0/1
 no ip address
 ip virtual-reassembly
 duplex auto
 speed auto
 pppoe enable
 pppoe-client dial-pool-number 1
 no cdp enable
!
interface ATM0/0/0
 no ip address
 shutdown
 no atm ilmi-keepalive
 dsl operating-mode auto
!
interface BRI0/1/0
 no ip address
 encapsulation hdlc
 shutdown
!
interface Dialer1
 ip address xxx.xx.xxx.xxx 255.255.255.0
 ip mtu 1492
 encapsulation ppp
 dialer pool 1
 dialer-group 1
 no keepalive
 no cdp enable
 ppp authentication chap callin
 ppp chap hostname qwerqwerqwerqwer
 ppp chap password 0 132412341234
 crypto ipsec client ezvpn nameOfTunnelGroup
!
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer1
!
access-list 1 permit 10.250.7.8 0.0.0.7


J=F6rg

--=20
J=F6rg Sch=FCtter                      http://www.schuetter.org/joerg
joerg@schuetter.org                http://www.lug-untermain.de/

Posted by Walter Roberson on March 5, 2006, 11:49 am
Please log in for more thread options

An extract of the ASA 55xx configuration would help here.

Hmmm, this link does not directly address what you are trying to
do, but some of the failure modes it describes might be
applicable to your situation:

http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_configuration_example09186a008032b637.shtml

Similar ThreadsPosted
ezvpn w/ router which has changing public address (PPPoE) March 5, 2006, 4:18 am
Changing the MAc address to VLAN interface or how to SPLIT a router in 2. December 2, 2006, 10:19 am
DHCP assigned address for ezVPN group December 18, 2005, 12:18 pm
Need help!! Interface answer to public address but not to private address July 13, 2006, 7:30 am
Using Cisco EZVpn together with router-to-router IPSEC config August 21, 2006, 6:14 am
Changing IP address of PIX June 19, 2006, 10:26 am
Changing PIX-PIX VPN address October 18, 2006, 7:51 am
changing pix internal address October 10, 2005, 7:44 pm
Cisco Pix 501 - changing mac address July 8, 2006, 8:39 am
506e changing the internal IP address November 4, 2005, 1:17 pm
Re: ezvpn fails on 1841 router with multiple dot1q intefaces September 2, 2006, 11:40 am
ezvpn fails on 1841 router with multiple dot1q intefaces August 29, 2006, 11:12 am
Dinamyc and static nat whit only one public ip address? August 24, 2005, 10:56 am
DHCP Address to 871W Public Interface - ACL Help May 7, 2006, 8:32 pm
asa 5500 failover (active/standby) public IP address change April 24, 2007, 7:17 am
Latest PostsForumRSS
NEWS: Samsung takes on the Apple iPad with the 7 inch Galaxy... Wireless Networking
c3560 port configuration Cisco Systems
Broadband 2010: A Big Slowdown [telecom] General Telecommunications Forum
Control Hot Water Circ Pump With X10? General Home Automation
Official Course CCNP TSHOOT 642-832 / Foundation Learning Gu... Cisco Certification
Speedflow Communications Honored for Innovation Voice-Over-IP
USB _to_ RJ45 (not from) connection Ethernet LAN
FAQ: Maximizing cable modem or DSL speed Cable Modems
CASH FOR CISCO - I BUY USED AND NEW EQUIPMENT & LOTS MOR... Telecom Technical
FAQ: Maximizing cable modem or DSL speed Digital Subscriber Line
How to set up Meridian 1 to "provide clock" to a C... Nortel Networks
New Discovery about WDM LAN and Telecom Cabling
Control Hot Water Circ Pump With X10? Home Automation
Text file to automate restoring a dropped VPN connection. Virtual Private Networks
Home Theater Installation Home Theater
Re: The Turkic Languages in a Nutshell Fiber Optics
sip Video Conferencing
Residential Cabling Guide Home Cabling Guide

Finally, an instantly downloadable book that saves you thousands in home improvement dollars! Enjoy living in 21st century technology-advanced home while increasing its selling value and competitive advantage on the real estate market. Whether your cabling is for home office or high-tech leisure, you can wire your home yourself or learn "wirish" to speak with your cabling contractors in their language!

Click Here to learn more