Cisco Ipsec Identity Hostname
The ISAKMP identity is the interface from which the remote router will
send ISAKMP messages to the local peer. If a router supports ISAKMP on
multiple interfaces, then hostnames should be used for ISAKMP identity.
To configure a router to send its hostname in its ISAKMP peer negotiations,
use the global command
<crypto isakmp identity {hostname | address}>.
The default is to use the router’s ISAKMP interface IP address.
If the hostname option is used to identify its ISAKMP negotiations,
the remote peer hosts need to have hostname-to-IP-address mapping,
achieved with <ip host {hostname} {IP address1} {IP Address 2…IP Address 8}>.
A router can also use DNS for hostname resolution, but local hostname
definitions are faster and don’t break if there is a DNS server problem.
Below is a pre-shared key configuration example between two routers. The local router
sends it hostname, and the remote machine sends its IP address.
First is the configuration on the local peer router (both the IP address and hostname
keys have been defined):
The configuration on the local router looks like this :
!
hostname outlan-rt01
!
!
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key secretkey address 192.168.10.3
crypto isakmp identity hostname
!
interface FastEthernet0/0
ip address 172.30.80.17 255.255.255.252
!
The configuration on the remote peer router looks like this:
!
hostname inlan-rt01
!
ip host outlan-rt01 172.30.80.17
!
!
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key secretkey address outlan-rt01
!
interface FastEthernet1/0
ip address 192.168.10.3 255.255.255.252