This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec Remote Access - Hostnames instead of WAN IP-Adress

Hello, first Post here so please bear with me.

i have searched through the forums but haven't found this specific anywhere

I've set up multiple UTMs in the past with all of them working as intended.

Now i'm at a customer where a large number of clients should use the self service portal for downloading their individual ipsec-profile (Almost exclusively ncp-clients from different brands if this is important). There is an internet connections Update planned in the not so distand future wich will include, changing the isp thus the public IP.

Normally this isn't so much of a problem because i could remote and change the ip manually in the ipsec config but the sheer amount of users in this case is to much. Is it possible to set a fix hostname (like in the openvpn section) to be used in the profile so that i can simply change the public dns record afterwards?

To be honest, this is the only thing i never really got to work with all of my utms. Normally this is a minor nusiance but in this case it's a major stress point for the onpremise supporters.

What i've did up until now:

set up a rdns for the public ip where the ipsec connection is accepting users. Changed the hostname. Set up a host object for the public IP in the Firewall itself. Basically i've tried everything that even remotly made sense to me for getting a hostname into that file.

There was one incident where the UTMs hostname was written into the ipsec config file but i can't reproduce this behaviour. I don't use the UTMs hostname for VPN-Connections, i have C-names setup with different records for the VPN-ID

Thanks in advance / best regards



This thread was automatically locked due to age.
Parents
  • Hallo and welcome to the UTM Community!

    I don't think this question has been presented here before.

    I also can't see a way to get an FQDN into the IPsec client config file - maybe you were thinking of the SSL VPN client???

    In any case, after the switchover to the new WAN IP, the users get that new IP in the new IPsec client config file when they go to the User Portal to download it - does that present a problem?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hallo and welcome to the UTM Community!

    I don't think this question has been presented here before.

    I also can't see a way to get an FQDN into the IPsec client config file - maybe you were thinking of the SSL VPN client???

    In any case, after the switchover to the new WAN IP, the users get that new IP in the new IPsec client config file when they go to the User Portal to download it - does that present a problem?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data