> Why do you think IPSec needs one fixed-IP endpoint? Certainly, things > won't work if both of you change IP addresses before the DNS updates, > but you seem to accept that. You can also get a fixed IP for free by > contacting one of the IPv6 tunnel brokers. Yes, this will be > IPv6-over-IPv4, which has its issues.
I've never seen an example where hostnames are used in place of static IP addresses in configuration files. Is it the case that anywhere I see an ip address (filenames, conf file values, etc), I could just as easily put in foo.dyndns.org? If my searching and/or comprehension skills are lacking, could you send a link this way? Thanks, Matt

