i've got 2 hosts on the internet with changing
IP-addresses at least every 24hours. each hosts
reconnects immediatelly and updates its DNS-entry (at
dyndns.org). using hostnames instead of IP-addr with
setkey works, but it immediatelly resolves them and
then these IP-addresses (in the policies) are never
updated again, thus the IPsec (transport) -connection
between the two is gone. ok, i could put a one-liner in
the ppp-up-script calling setkey, but if the two hosts
don't redial about the same time, i always have to
check if the peer's DNS-entry has changed and then call
setkey again. so using FQDNs would be much nicer; this
was possible with FreeS/WAN, IIRC. so, the DNS was
always asked when phase 1 started -- of course this is
somewhat lavish, but otherwise i'd have to check
automanually (cron) (much more lavish in case of a
seldomly used IPsec-connection).
is this possible with recent ipsec-tools and linux 2.6?
are there any plans to implement this feature? TIA
Log in to post a comment.