Blame

b0611b Samuli Seppänen 2025-02-11 10:25:37 1
# Can OpenVPN handle the situation where both ends of the connection are dynamic?
2
3
Yes.
4
5
A prerequisite of this method is that you subscribe to a service such as [dyndns.org](http://www.dyndns.com/) that lets you conveniently point an internet domain name to a dynamic address (or you can do it yourself if you have control over a DNS server that exists on a machine having a static IP address).
6
7
The crux of this method is in the 'timeouts' section of the config file below, or more specifically the 'ping' and 'ping-restart' options. Basically, if for whatever reason, OpenVPN doesn't receive a ping from its peer during a 300 second period (as would happen if its peer changed addresses), it will restart. When it restarts, it will re-resolve myremote.mydomain.com to get the new IP address. This method assumes that you are using a dynamic DNS service that lets you immediately update your domain name with your current dynamic address.
8
9
Using this technique, OpenVPN will essentially "follow" a dynamic DNS address as it changes.
10
11
Here is the config file example:
12
```
13
remote myremote.mydomain.com
14
dev tun
15
ifconfig 10.1.0.2 10.1.0.1
16
up ./up-script # optional
17
18
# crypto config
19
replay-persist replay-persist-file # optional (1.4.0 or above)
20
21
# TLS config (or omit TLS security by using a pre-shared key
22
# such as 'secret static.key').
23
tls-client
24
ca key/my-ca.crt
25
cert key/my-cert.crt
26
key key/my-key.key
27
tls-auth key/my-tls-password # optional
28
29
# timeouts
30
ping 15
31
ping-restart 300 # 5 minutes
32
resolv-retry 300 # 5 minutes
33
persist-tun
34
persist-key
35
36
# compression (optional)
37
comp-lzo
38
39
# UID (optional)
40
user nobody
41
group nobody
42
43
# verbosity (optional)
44
verb 4
45
```
46
47
On the other end of the connection, you would duplicate the above config file but change 'remote' appropriately, and swap the ifconfig addresses.
48
49
If you are using TLS security, then also change 'tls-client' to 'tls-server', add a 'dh' file for the Diffie-Hellman file, and change 'cert' and 'key' to match your appropriate local cert and key.
50
51
This setup requires that each machine have a dynamic DNS name which is updated automatically when DHCP causes an address change. Such an automatic update can be accomplished by using a tool such as [ddclient](http://sourceforge.net/apps/trac/ddclient).
52
53
**ddclient** should be called by your **/etc/dhcpc/dhcpcd-eth0.exe** file (replace "eth0" in the filename with the appropriate network device name):
54
```
55
/usr/sbin/ddclient -daemon=0 -syslog -use=ip -ip=$1
56
```
57
58
Here is a sample **/etc/ddclient.conf** file:
59
```
60
######################################################################
61
##
62
## TODO: change mylogin, mypassword, myremote. mydomain.com
63
##
64
######################################################################
65
66
login=mylogin # default login
67
password=mypassword # default password
68
#mx=mx.for.your.host # default MX
69
#backupmx=yes|no # host is primary MX?
70
#wildcard=yes|no # add wildcard CNAME?
71
72
##
73
##
74
## dyndns.org custom addresses
75
##
76
## (supports variables: wildcard,mx,backupmx)
77
##
78
custom=yes
79
server=members.dyndns.org,
80
protocol=dyndns2
81
myremote.mydomain.com
82
```