Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Site-to-site VPN with non-static IP address

    Scheduled Pinned Locked Moved IPsec
    7 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fazevedo
      last edited by

      Looking for help on how to configure a site-to-site VPN.

      The scenario includes a remote branch office using an SG-1100 that needs to connect (site-to-site) to the main site (using also pfSense) but the remote branch office does not have a static IP Address.

      Currently I have a site-to-site tunnel established with the current IP address. The ISP, however, changes the IP address every other couple of days. This results in the VPN going down and manually have to go to both ends of the tunnel to update with the new IP address of the remote branch.

      Any ideas on how I could establish the VPN from the remote branch and bring up the tunnel automatically when the IP address changes?

      J 1 Reply Last reply Reply Quote 0
      • J
        Jarhead @fazevedo
        last edited by

        @fazevedo Use a dynamic dns service.
        Go to Services/Dynamic DNS and you'll see a list of supported sites. Some are free, some paid.

        F 1 Reply Last reply Reply Quote 0
        • F
          fazevedo @Jarhead
          last edited by

          @jarhead I was trying to avoid that... but if there is no other solution...

          V J 2 Replies Last reply Reply Quote 0
          • V
            viragomann @fazevedo
            last edited by

            @fazevedo
            Should also be possible with a dynamic IP on one site, but only this one can initiate the connection then.

            In the P1 settings of the main office you have to state "0.0.0.0" at "Remote Gateway". So it accepts connections from anywhere.

            1 Reply Last reply Reply Quote 0
            • J
              Jarhead @fazevedo
              last edited by

              @fazevedo said in Site-to-site VPN with non-static IP address:

              @jarhead I was trying to avoid that... but if there is no other solution...

              Why avoid it??
              The free sites work great and it doesn't cause any harm.
              What would be your reason to avoid it?

              F 1 Reply Last reply Reply Quote 0
              • F
                fazevedo @Jarhead
                last edited by

                @jarhead said in Site-to-site VPN with non-static IP address:

                What would be your reason to avoid it?

                Just plain old security paranoia...

                J 1 Reply Last reply Reply Quote 0
                • J
                  Jarhead @fazevedo
                  last edited by

                  @fazevedo How would that be any different than the actual IP address?
                  You don't have to tell anyone what the domain name you chose is. There's literally no security concern any different than having a public IP.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.