<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Dynamic IP and remote locations]]></title><description><![CDATA[<p dir="auto">I'm attempting to create a  site-to-site VPN using IPSEC with two pfsense routers.  Each site has dynamic public IP addresses. I'm using fully qualified host names as addresses for the gateways.  Name resolution for these hostnames is provided by Dyndns.</p>
<p dir="auto">I'm able to successfully create a tunnel.  BUT when an IP changes on one side of the tunnel, I can only reestablish it by reconnecting from the side whose IP DIDN'T change.</p>
<p dir="auto">In other words, if I have a site-to-site vpn connection and the IP address of the site I am physically at changes, I need someone at the remote site to reestablish the connection (or alternatively access the firewall myself over the public network).</p>
<p dir="auto">Is this the expected IPSEC behavior?  If it is, how can I  maintain connections with remote locations?</p>
<p dir="auto">Or am I just doing something wrong?</p>
<p dir="auto">Here is my setup on one of the servers (I replaced my DynDNS hostname with "example.com")</p>
<p dir="auto">Internet Protocol: IPv4   <br />
Interface: WAN <br />
Remote gateway:  one.example.com</p>
<p dir="auto">Authentication method: Mutual PSK   <br />
Negotiation mode: aggressive<br />
My identifier User distinguished name  one@example.com<br />
Peer identifier User distinguished name  two@example.com <br />
Pre-Shared Key  xxxxx<br />
Policy Generation Default<br />
Proposal Checking Default <br />
Encryption algorithm AES  256 bits <br />
Hash algorithm SHA1 <br />
DH key group 1 (768 bit)<br />
Lifetime  seconds  86400</p>
<p dir="auto">Advanced Options<br />
NAT Traversal Enable<br />
Enable DPD<br />
10 seconds<br />
Delay between requesting peer acknowledgement.</p>
<p dir="auto">5 retries<br />
Number of consecutive failures allowed before disconnect.</p>
]]></description><link>https://forum.netgate.com/topic/70288/dynamic-ip-and-remote-locations</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 01:31:02 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/70288.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 14 Jun 2014 23:07:28 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Dynamic IP and remote locations on Thu, 19 Jun 2014 04:50:51 GMT]]></title><description><![CDATA[<p dir="auto">Things got worse.  Racoon failed to even attempt to connect.  Specifically, hitting the connect icon returned immediately and there was no record of any connection attempt in the log. Deleted the phase one and phase two entries, and re-entering them.  Seems to be working now.</p>
<p dir="auto">Must have been some sort of corruption in the configuration.</p>
]]></description><link>https://forum.netgate.com/post/468155</link><guid isPermaLink="true">https://forum.netgate.com/post/468155</guid><dc:creator><![CDATA[work_permit]]></dc:creator><pubDate>Thu, 19 Jun 2014 04:50:51 GMT</pubDate></item></channel></rss>