Layer 3 tunnel with Dynamic IP address

greipseclayer3tunnel

I want to ask whether it is possible to configure Layer 3 Tunnel with the two end points/interfaces have dynamic IP address?

If the interface IP change, the tunnel will have to be re-negotiated, is that right?

The two L3 Tunneling protocol I know are GRE and IPSec. GRE definitely need static IP. Does IPSec need static IP as well?

Thank you

Best Answer

The short answer to answer your question is No. IPSEC needs at least one endpoint with a static IP.

The slightly longer answer is: I have seen at least one SOHO router that allowed you to specify a DNS entry as the endpoint, so if you find a router that has this feature you may be able to get around this limitation with a Dynamic DNS service to track at least on of the two dynamic IPs and map them to a resolvable hostname.