# FlexVPN Site-to-Site Smart Defaults

**URL:** https://forum.networklessons.com/t/flexvpn-site-to-site-smart-defaults/13149
**Category:** Lessons Discussion
**Created:** [December 22, 2020, 3:23pm UTC](https://forum.networklessons.com/t/flexvpn-site-to-site-smart-defaults/13149 "2020-12-22T15:23:34Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 22, 2020, 3:23pm UTC](https://forum.networklessons.com/t/flexvpn-site-to-site-smart-defaults/13149/1 "2020-12-22T15:23:34Z")

</div>

This topic is to discuss the following lesson:

> **[FlexVPN Site-to-Site Smart Defaults](https://networklessons.com/vpn/flexvpn-site-to-site-smart-defaults)**
>
> This lesson explains how to configure Cisco FlexVPN Site-to-Site with smart defaults on Cisco IOS routers.

---

<div class="post-metadata">

### Author: ![btandu](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/b/9dc877/32.png) [@btandu](https://forum.networklessons.com/u/btandu)
#### Post date: [September 23, 2022, 11:09am UTC](https://forum.networklessons.com/t/flexvpn-site-to-site-smart-defaults/13149/2 "2022-09-23T11:09:12Z")

</div>

Hello,

Please would you assist to clarify the value that should be on `peer` command under `crypto ikev2 keyring IKEV2_KEYRING`.

e,g.:

```auto
crypto ikev2 keyring IKEV2_KEYRING
       peer xxxx

```

what represents the xxxx?

Thanks

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [September 26, 2022, 6:15am UTC](https://forum.networklessons.com/t/flexvpn-site-to-site-smart-defaults/13149/3 "2022-09-26T06:15:09Z")

</div>

Hello Byorn

The `peer xxxx` command is used to define the peer to peer group. It is a word you use to define that group. You can choose whatever you want. In the following lesson, Rene chooses to use “R2” which is the name of the remote router to which he is connecting. Take a look at this lesson which describes FlxeVPN site to site configurations:

> **[FlexVPN Site-to-Site Smart Defaults](https://networklessons.com/vpn/flexvpn-site-to-site-smart-defaults)**
>
> This lesson explains how to configure Cisco FlexVPN Site-to-Site with smart defaults on Cisco IOS routers.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![wwwillster07](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/w/67e7ee/32.png) [@wwwillster07](https://forum.networklessons.com/u/wwwillster07)
#### Post date: [June 9, 2025, 2:04am UTC](https://forum.networklessons.com/t/flexvpn-site-to-site-smart-defaults/13149/4 "2025-06-09T02:04:16Z")

</div>

The ikev2profile kind of came out of left field with this:

```
match identity remote fqdn R2.NWL.LAB
```

There’s been no mention of dns or a dns server, unless I missed it, no discussion about configuring the ip-domain-lookup functionality. Does Cisco just assume you can put in any fqdn and it just works? Up to this point it’s just been ip addresses…

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [June 10, 2025, 7:15am UTC](https://forum.networklessons.com/t/flexvpn-site-to-site-smart-defaults/13149/5 "2025-06-10T07:15:36Z")

</div>

Hello William

You’re right, it is confusing! I believe the source of the confusion comes from the use of the `fqdn` keyword.

The use of FQDNs in IKEv2 profiles doesn’t require DNS resolution because these FQDN values simply serve as static identifiers rather than actual DNS queries.

The `match identity remote fqdn` command compares the peer’s declared identity against a preconfigured string. Peers exchange identities during IKEv2 negotiation as raw strings, not IP addresses. This FQDN value simply acts as an authentication fingerprint. Both devices must have matching configurations for local identity (e.g., `identity local fqdn R1.NWL.LAB`) and remote identity (e.g., `match identity remote fqdn R2.NWL.LAB`).

The approach is analogous to using pre-shared keys (PSKs) - both ends need identical configurations, but no underlying DNS infrastructure is required. This makes it suitable for static site-to-site VPNs where IP addresses might change but organizational naming remains consistent.

For the command, you can actually input whatever you want! For example you can issue the following command:

`match identity remote fqdn helloworld`

If the string matches, it will work. There are other options to use such as email, domain, or key ID. See this [command reference](https://www.cisco.com/c/en/us/td/docs/routers/sdwan/command/iosxe/qualified-cli-command-reference-guide/m-crypto-commands.html#Cisco_Command_Page.dita_33cd5e04-1f52-436a-9660-099c9734b64a) for more details.

So these values simply serve as labels, but it is useful to have them use meaningful values rather than some dummy value like helloworld that I mentioned before. Does that make sense?

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![wwwillster07](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/w/67e7ee/32.png) [@wwwillster07](https://forum.networklessons.com/u/wwwillster07)
#### Post date: [June 10, 2025, 10:28pm UTC](https://forum.networklessons.com/t/flexvpn-site-to-site-smart-defaults/13149/6 "2025-06-10T22:28:05Z")

</div>

Very helpful! Thanks
