<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Static to dynamic]]></title><description><![CDATA[<p dir="auto">Hi all</p>
<p dir="auto">I have a pfsense 1.2 box at the main office with static ip and I would like to connect remote offices that have adsl lines with dynamic ips.<br />
Remote offices are connected with cisco 877 routers.<br />
Tunnels with the temporary ip (cisco side) works.<br />
I noticed that I cannot use dynamic dns fqdn in the pfsense config.</p>
<p dir="auto">Is there some trick to solve this problem ?<br />
Can I use mobile client function to connect routers instead single pc ?</p>
<p dir="auto">thanks</p>
<p dir="auto">Giacomo</p>
]]></description><link>https://forum.netgate.com/topic/10742/static-to-dynamic</link><generator>RSS for Node</generator><lastBuildDate>Fri, 08 May 2026 09:30:47 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/10742.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 05 Sep 2008 22:13:13 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Static to dynamic on Fri, 10 Oct 2008 12:43:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/capitangiaco">@<bdi>capitangiaco</bdi></a>:</p>
<blockquote>
<p dir="auto">and please don't bore with the not stable story…. 1.3 is at the moment, the only way to use ipsec dynamic peers<br />
Giacomo</p>
</blockquote>
<p dir="auto">Not true. 5 sites with dynamic IP only, site-to-site tunnels, pfS 1.2 with help of little custom script and crone job, up-time 7 months 20 days. So, it is possible but someone need to put some extra effort to make it work.</p>
<p dir="auto">Sasa</p>
]]></description><link>https://forum.netgate.com/post/183025</link><guid isPermaLink="true">https://forum.netgate.com/post/183025</guid><dc:creator><![CDATA[ssbaksa]]></dc:creator><pubDate>Fri, 10 Oct 2008 12:43:08 GMT</pubDate></item><item><title><![CDATA[Reply to Static to dynamic on Thu, 09 Oct 2008 00:08:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/phospher">@<bdi>phospher</bdi></a>:</p>
<blockquote>
<p dir="auto">1.3 is alpha release. it's not stable and not meant for production use. however, you may want to head over to the 1.3 forum and post this issue for help.</p>
</blockquote>
<p dir="auto">isn't a version problem, that warning is a racoon-cisco issue, I can see the '<em>racoon: WARNING: ignore RESPONDER-LIFETIME notification.</em>' also in 1.2 logs<br />
and please don't bore with the not stable story…. 1.3 is at the moment, the only way to use ipsec dynamic peers</p>
<p dir="auto">Giacomo</p>
]]></description><link>https://forum.netgate.com/post/182898</link><guid isPermaLink="true">https://forum.netgate.com/post/182898</guid><dc:creator><![CDATA[capitangiaco]]></dc:creator><pubDate>Thu, 09 Oct 2008 00:08:36 GMT</pubDate></item><item><title><![CDATA[Reply to Static to dynamic on Wed, 08 Oct 2008 03:57:06 GMT]]></title><description><![CDATA[<p dir="auto">1.3 is alpha release. it's not stable and not meant for production use. however, you may want to head over to the 1.3 forum and post this issue for help.</p>
]]></description><link>https://forum.netgate.com/post/182835</link><guid isPermaLink="true">https://forum.netgate.com/post/182835</guid><dc:creator><![CDATA[phospher]]></dc:creator><pubDate>Wed, 08 Oct 2008 03:57:06 GMT</pubDate></item><item><title><![CDATA[Reply to Static to dynamic on Sun, 05 Oct 2008 10:54:00 GMT]]></title><description><![CDATA[<p dir="auto">from racoon logs I can see this warning:<br />
10-05-2008 12:15:38 System3.Info 192.168.1.254 Oct  5 12:16:07 racoon: WARNING: ignore RESPONDER-LIFETIME notification.</p>
<p dir="auto">When a remote peer change ip, sometimes pfsense keep the old Security Association and I must press save in vpn -&gt; ipsec.<br />
(the Prefer older IPsec SAs is disabled)</p>
<p dir="auto">Giacomo</p>
]]></description><link>https://forum.netgate.com/post/182698</link><guid isPermaLink="true">https://forum.netgate.com/post/182698</guid><dc:creator><![CDATA[capitangiaco]]></dc:creator><pubDate>Sun, 05 Oct 2008 10:54:00 GMT</pubDate></item><item><title><![CDATA[Reply to Static to dynamic on Sun, 14 Sep 2008 12:58:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fastcon68">@<bdi>fastcon68</bdi></a>:</p>
<blockquote>
<p dir="auto">Until verison 1.3 that supports DYN names in the IPSEC setup I do the following.  I use a Dynamic DNS client on a server or client at the other end.  In my description I put the Dynamic DNS name.</p>
<p dir="auto">I monitor the endpoint connections and because the dsl connections seems keep a IP address for several days.  I then update any end points that have changed.  The connection comes backup and I have no real issues with this solution.</p>
<p dir="auto">RC</p>
</blockquote>
<p dir="auto">I upgraded to 1.3-alpha and now I can use dyndns hostname in the tunnel config, and with the dyndns client installed on a pc behind the remote routers I refresh the ip.<br />
It is working.<br />
The only problem now is that the vpn comes up only when It is started from the remote site (dynamic ip, cisco router).</p>
<p dir="auto">thanks</p>
<p dir="auto">Giacomo</p>
]]></description><link>https://forum.netgate.com/post/181561</link><guid isPermaLink="true">https://forum.netgate.com/post/181561</guid><dc:creator><![CDATA[capitangiaco]]></dc:creator><pubDate>Sun, 14 Sep 2008 12:58:42 GMT</pubDate></item><item><title><![CDATA[Reply to Static to dynamic on Sat, 13 Sep 2008 20:26:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/capitangiaco">@<bdi>capitangiaco</bdi></a>:</p>
<blockquote>
<p dir="auto">Can I use mobile client function to connect routers instead single pc ?</p>
</blockquote>
<p dir="auto">The static side with pfsense 1.2 and enabled mobile option. The other side with a pfsense 1.2 could connect in an aggressive to the static side. The works as it should. All Clients behind the dynamic pfsense can connect the other side.</p>
<p dir="auto">Regards<br />
heiko</p>
]]></description><link>https://forum.netgate.com/post/181537</link><guid isPermaLink="true">https://forum.netgate.com/post/181537</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Sat, 13 Sep 2008 20:26:37 GMT</pubDate></item><item><title><![CDATA[Reply to Static to dynamic on Sat, 13 Sep 2008 15:39:25 GMT]]></title><description><![CDATA[<p dir="auto">Until verison 1.3 that supports DYN names in the IPSEC setup I do the following.  I use a Dynamic DNS client on a server or client at the other end.  In my description I put the Dynamic DNS name.</p>
<p dir="auto">I monitor the endpoint connections and because the dsl connections seems keep a IP address for several days.  I then update any end points that have changed.  The connection comes backup and I have no real issues with this solution.</p>
<p dir="auto">RC</p>
]]></description><link>https://forum.netgate.com/post/181532</link><guid isPermaLink="true">https://forum.netgate.com/post/181532</guid><dc:creator><![CDATA[fastcon68]]></dc:creator><pubDate>Sat, 13 Sep 2008 15:39:25 GMT</pubDate></item></channel></rss>