Blame
| b0611b | Samuli Seppänen | 2025-02-11 10:25:37 | 1 | # Can OpenVPN handle the situation where both ends of the connection are dynamic? |
| 2 | ||||
| 3 | Yes. |
|||
| 4 | ||||
| 5 | A prerequisite of this method is that you subscribe to a service such as [dyndns.org](http://www.dyndns.com/) that lets you conveniently point an internet domain name to a dynamic address (or you can do it yourself if you have control over a DNS server that exists on a machine having a static IP address). |
|||
| 6 | ||||
| 7 | The crux of this method is in the 'timeouts' section of the config file below, or more specifically the 'ping' and 'ping-restart' options. Basically, if for whatever reason, OpenVPN doesn't receive a ping from its peer during a 300 second period (as would happen if its peer changed addresses), it will restart. When it restarts, it will re-resolve myremote.mydomain.com to get the new IP address. This method assumes that you are using a dynamic DNS service that lets you immediately update your domain name with your current dynamic address. |
|||
| 8 | ||||
| 9 | Using this technique, OpenVPN will essentially "follow" a dynamic DNS address as it changes. |
|||
| 10 | ||||
| 11 | Here is the config file example: |
|||
| 12 | ``` |
|||
| 13 | remote myremote.mydomain.com |
|||
| 14 | dev tun |
|||
| 15 | ifconfig 10.1.0.2 10.1.0.1 |
|||
| 16 | up ./up-script # optional |
|||
| 17 | ||||
| 18 | # crypto config |
|||
| 19 | replay-persist replay-persist-file # optional (1.4.0 or above) |
|||
| 20 | ||||
| 21 | # TLS config (or omit TLS security by using a pre-shared key |
|||
| 22 | # such as 'secret static.key'). |
|||
| 23 | tls-client |
|||
| 24 | ca key/my-ca.crt |
|||
| 25 | cert key/my-cert.crt |
|||
| 26 | key key/my-key.key |
|||
| 27 | tls-auth key/my-tls-password # optional |
|||
| 28 | ||||
| 29 | # timeouts |
|||
| 30 | ping 15 |
|||
| 31 | ping-restart 300 # 5 minutes |
|||
| 32 | resolv-retry 300 # 5 minutes |
|||
| 33 | persist-tun |
|||
| 34 | persist-key |
|||
| 35 | ||||
| 36 | # compression (optional) |
|||
| 37 | comp-lzo |
|||
| 38 | ||||
| 39 | # UID (optional) |
|||
| 40 | user nobody |
|||
| 41 | group nobody |
|||
| 42 | ||||
| 43 | # verbosity (optional) |
|||
| 44 | verb 4 |
|||
| 45 | ``` |
|||
| 46 | ||||
| 47 | On the other end of the connection, you would duplicate the above config file but change 'remote' appropriately, and swap the ifconfig addresses. |
|||
| 48 | ||||
| 49 | If you are using TLS security, then also change 'tls-client' to 'tls-server', add a 'dh' file for the Diffie-Hellman file, and change 'cert' and 'key' to match your appropriate local cert and key. |
|||
| 50 | ||||
| 51 | This setup requires that each machine have a dynamic DNS name which is updated automatically when DHCP causes an address change. Such an automatic update can be accomplished by using a tool such as [ddclient](http://sourceforge.net/apps/trac/ddclient). |
|||
| 52 | ||||
| 53 | **ddclient** should be called by your **/etc/dhcpc/dhcpcd-eth0.exe** file (replace "eth0" in the filename with the appropriate network device name): |
|||
| 54 | ``` |
|||
| 55 | /usr/sbin/ddclient -daemon=0 -syslog -use=ip -ip=$1 |
|||
| 56 | ``` |
|||
| 57 | ||||
| 58 | Here is a sample **/etc/ddclient.conf** file: |
|||
| 59 | ``` |
|||
| 60 | ###################################################################### |
|||
| 61 | ## |
|||
| 62 | ## TODO: change mylogin, mypassword, myremote. mydomain.com |
|||
| 63 | ## |
|||
| 64 | ###################################################################### |
|||
| 65 | ||||
| 66 | login=mylogin # default login |
|||
| 67 | password=mypassword # default password |
|||
| 68 | #mx=mx.for.your.host # default MX |
|||
| 69 | #backupmx=yes|no # host is primary MX? |
|||
| 70 | #wildcard=yes|no # add wildcard CNAME? |
|||
| 71 | ||||
| 72 | ## |
|||
| 73 | ## |
|||
| 74 | ## dyndns.org custom addresses |
|||
| 75 | ## |
|||
| 76 | ## (supports variables: wildcard,mx,backupmx) |
|||
| 77 | ## |
|||
| 78 | custom=yes |
|||
| 79 | server=members.dyndns.org, |
|||
| 80 | protocol=dyndns2 |
|||
| 81 | myremote.mydomain.com |
|||
| 82 | ``` |
