Score:0

DynDNS - Solution for site-to-site VPN's over 5G backup internet?

nu flag

One of our sites have moved to a new locaiton and I have been battling with the fibre provider to install the new connection at the site. Currently, we run a 5G connection as a backup connection at this site (as a secondary WAN on our Firewall), but due to the IP changes (which is static on the fibre, but not on 5G), our VPN to this side is down of course.

My question is, would DynDNS be a solution for the VPN to stay up - granted to change the local ID of this VPN to the DynDNS hostname? Secondly, would there be any delays when the IP changes (like drop the connection briefly while it updates) or any other considerations I need to take into account?

Thank you for your assistance.

Score:0
vn flag

DynDNS or a similar dynamic IP system would be a solution, yes - though if your VPN system assumes persistent connections it might run into trouble when the IP address changes. It should be able to recover from that, of course, but that could be a disruption.

There would always be delays when the IP changes - DynDNS is not instantaneous, something on the end point periodically talks to the server, which informs the server what the current IP is, so there is that potential latency between when the IP changes and when the next connection is made. In theory that can be minimized by having the DynDNS client watch for DHCP incoming, and contact the server when that happens, though that depends on having the DynDNS client be installed as part of the firewall firmware. Additionally, there is some concern with the DNS time-to-live. To wit, if the DNS server specifies a 5-minute timeout on the DNS, there potentially would still be a 5-minute gap where your VPN would be using stale, cached DNS information which might no longer match the state of affairs.

I'm assuming from your description that there is a static IP on the old location. Is it possible to have the new location connect to the old via VPN, then set a route in your firewall to route everything from the old location destined for the new one through that connection? I'll freely admit that might be problematic, the new campus VPN might not properly translate incoming packets without there being an existing conversation initiated by the new campus,

Francois Botha avatar
nu flag
Thank you tsc_chazz, this is useful and helpful information. The Firewall does have an application for various DDNS providers to assist with continuous checking and updates at set intervals. I think this is enough information for me to go ahead and test this and hope for a positive outcome. I will test this and provide feedback on the observations over the next couple of days. I appreciate your input!
Francois Botha avatar
nu flag
Just to report back on this, tsc_chazz, this works wonderfully. Thank you for the advice. We are using No-IP DDNS service and the connection works flawlessly over the Sophos firewall.
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.