Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Allow traffic from dynamic IP address

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      brandilton
      last edited by

      I have a phone system behind a pfsense.  I want to open up the proper ports so that i can have remote phones, but i want to limit who can connect to only a few IP addresses.  Problem is that one of the people that needs a remote phone uses an ISP that will not give him a static ip address.  Is there a way i can create a firewall rule that checks a dyndns (or similar) type of address?

      1 Reply Last reply Reply Quote 0
      • B Offline
        blak111
        last edited by

        There isn't any supported way of doing that. Perhaps he could use a router at home that supports a VPN to connect into your network.
        Another possibility that isn't as secure is to make an allow rule for the ISP's subnet that he always ends up in. (eg. 129.128.0.0/22)

        1 Reply Last reply Reply Quote 0
        • jimpJ Offline
          jimp Rebel Alliance Developer Netgate
          last edited by

          A mobile IPsec tunnel would be great for this kind of situation, and would remain secure.

          There are some ways to use hostnames in rules, such as using a hostname in an alias instead of directly in the rule, but there are some drawbacks to that. I forget exactly what they are though. Something about needing a script to update the resolved hostname now and then.

          There was a recent discussion on the forums, or perhaps the support list, try searching for some variation of the keywords "dynamic host alias".

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • G Offline
            Gob
            last edited by

            I find that using a voip phone over an IPSEC VPN tunnel affects the call quality quite seriously. I guess it is the overhead of the encryption.

            I have the same problem with a couple of home workers. Will try out the Alias hostname.

            Thanks

            If I fix one more thing than I break in a day, it's a good day!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.