Cisco – FQDN’s in crypto maps and AAA servers possible with dynamic DNS resolution? Cisco ASA

aaaciscocisco-asafirewall

Can I use FQDN's in crypto maps when setting a peer (where I'd normally use an IP), and can I use FQDN's when defining an LDAP Server or any other AAA Server in a server group? In both cases the FQDN's would have to be resolved by calls to an external DNS server (FQDN objects).

If the answer is yes, please provide a quick example of how to do that.
I already know how to use FQDN's in ACL's, setup external DNS and validate the ASA is resolving those properly.

Best Answer

Yes, according to the Cisco documentation (v8.4), you can use a hostname most places you use an IP address.

Here's an example lifted from the documentation:

ne-asa(config)#aaa-server LDAP_SRV_GRP (inside) host myserver.networkegineering.stackexchage.com
ne-asa(config-aaa-server-host)#ldap-attribute-map ne-MAP