IPsec VPN tunnels usually require a static WAN IP address for at least one router. However in situations where both routers at each end of the VPN tunnel have a dynamic IP address (perhaps connected to 3G/4G network) using Main mode for VPN tunnel configuration is not possible. In this case the Aggressive Mode option is available which uses Peer ID to establish the VPN tunnel.

This video shows you the configuration process using Aggressive Mode to establish a VPN tunnel between two sites.

Click here to watch this video