ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Question about pfSense Site to Site VPN

    IT Discussion
    4
    87
    18.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch @IT-ADMIN
      last edited by

      @IT-ADMIN said:

      i'm using openDNS

      I have no hard evidence to back this up, but I feel that OpenDNS is slow to update compared to Google DNS.

      But you will always have this issue with any DDNS solution.

      Since you are using pfSense, I would setup OpenVPN instead of IPSEC. OpenVPN can handle a dynamic changing client much better than IPSEC does. If you are already using OpenVPN, then it is simply a matter of reconfiguring one side to be dynamic and not rely on the DDNS.

      IT-ADMINI 1 Reply Last reply Reply Quote 0
      • IT-ADMINI
        IT-ADMIN @JaredBusch
        last edited by

        @JaredBusch yes Sir i'm using OpenVPN, and feedns.afraid.org as DDNS, and i'm using the built-in DDNS updater in pfsense,

        1 Reply Last reply Reply Quote 0
        • IT-ADMINI
          IT-ADMIN
          last edited by

          do you mean by not relying on DDNS that i have to change the IP myself in each IP change ????

          scottalanmillerS JaredBuschJ 2 Replies Last reply Reply Quote 0
          • IT-ADMINI
            IT-ADMIN
            last edited by

            what about having each box a client and server in the same time, Mr Scott don't like this idea,
            what about you Sir

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @IT-ADMIN
              last edited by

              @IT-ADMIN said:

              what about having each box a client and server in the same time, Mr Scott don't like this idea,
              what about you Sir

              I don't believe that you can.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @IT-ADMIN
                last edited by

                @IT-ADMIN said:

                do you mean by not relying on DDNS that i have to change the IP myself in each IP change ????

                That's an option but I would prefer the DNS delay.

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  How often does your IP address change?

                  1 Reply Last reply Reply Quote 0
                  • IT-ADMINI
                    IT-ADMIN
                    last edited by

                    sometimes one week, sometimes 4 days, it depend

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @IT-ADMIN
                      last edited by

                      @IT-ADMIN said:

                      sometimes one week, sometimes 4 days, it depend

                      Wow, that is really short.

                      IT-ADMINI 1 Reply Last reply Reply Quote 0
                      • IT-ADMINI
                        IT-ADMIN
                        last edited by

                        currently i check every time my public ip to make sure that it is still fixed to make sure that the 2 office are connected, i wish to make this happen automatically but unfortunately DDNS despair me

                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @IT-ADMIN
                          last edited by

                          @IT-ADMIN said:

                          currently i check every time my public ip to make sure that it is still fixed to make sure that the 2 office are connected, i wish to make this happen automatically but unfortunately DDNS despair me

                          I assume that you don't have the ability to get static IPs? Have you looked into Hamachi?

                          1 Reply Last reply Reply Quote 0
                          • IT-ADMINI
                            IT-ADMIN @scottalanmiller
                            last edited by IT-ADMIN

                            @scottalanmiller yes, and also our ISP makes it difficult to possess static IP, he force you to buy a subnet of 8 static ip, and the price is very expensive, because here in qatar exist only one ISP (landline provider) for this reason they do what they want,

                            1 Reply Last reply Reply Quote 0
                            • IT-ADMINI
                              IT-ADMIN
                              last edited by

                              and also they force you to change you current wire installation and make a new one

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @IT-ADMIN
                                last edited by

                                @IT-ADMIN said:

                                and also they force you to change you current wire installation and make a new one

                                Wow. Is it a government controlled monopoly or as the market just not created competition (yet)?

                                IT-ADMINI 1 Reply Last reply Reply Quote 0
                                • IT-ADMINI
                                  IT-ADMIN @scottalanmiller
                                  last edited by

                                  @scottalanmiller exactly, it is a government ISP that don't have any competition, so they have freedom to do what they want

                                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @IT-ADMIN
                                    last edited by

                                    @IT-ADMIN said:

                                    @scottalanmiller exactly, it is a government ISP that don't have any competition, so they have freedom to do what they want

                                    I see. That is unfortunate that instead of working to enable business that they use it to make money via the ISP directly. Iceland does something similar with a central ISP but provides high speed, great access to everyone.

                                    1 Reply Last reply Reply Quote 0
                                    • IT-ADMINI
                                      IT-ADMIN
                                      last edited by

                                      hhhh, can you imagine our ISP max ADSL bandwidth

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller
                                        last edited by

                                        Hamachi would be "low" cost and should do what you need. I prefer Pertino but in your use case, gateway to gateway, it doesn't have an offering yet.

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller @IT-ADMIN
                                          last edited by

                                          @IT-ADMIN said:

                                          hhhh, can you imagine our ISP max ADSL bandwidth

                                          They are still using ADSL? That is horrible. Qatar is such a rich country, they could go all fiber overnight and really enable business there. The opportunities being missed are tragic.

                                          1 Reply Last reply Reply Quote 0
                                          • IT-ADMINI
                                            IT-ADMIN
                                            last edited by

                                            currently they are working in fiber optic, but only in some region not all qatar

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 1 / 5
                                            • First post
                                              Last post