Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Dynamic DNS update cadence in 20.0?

I could swear that back in the day (maybe 18.5 or 19) that DDNS updated every five or 10 minutes and you could see this in the logs. We were using Google -- which has now sold its business -- and have switched to Cloudflare, and I'm not seeing any updates. Should it be updating (and logging) every few minutes?

If not, is there a way to force SFOS to test the mechanism to make sure I have the correct key, etc?

(The IP from the ISP is not changing and hasn't changed in years, so forcing it to change and trigger a DDNS update isn't going to happen.)



This thread was automatically locked due to age.
Parents
  • Hi Wayne,

    screenshots of the theory, the practise as you have noted is very different. My XG updated the DDNS at 2258 24/5/24, the current time 0819 25/5/24.

    Also, I would expected the IPv6 DDNS would have been added after the inclusion of IPv6 DHCP-PD.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • As far as i remember (not using DDNS at the moment) it only protocols in DDNS logviewer, if there was a change. 

    __________________________________________________________________________________________________________________

  • Mine doesn't change, it is sticky address I have had since I signed up with this RSP about 12 months ago after they did a network re-arrangement.

    Ian

    What about DHCP renewals possibly triggering the DDNS update, maybe?

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • At one time, it logged every X minutes. This could have been a Google DDNS thing, or it could have been an older SFOS (18 or 19). Definitely not doing it now, and I'm worried that I have the incorrect credentials and when it finally needs to fire it won't work. (And I won't be local.)

    So any tip on forcing it to fire to test it would be great. (My ISP allocates an IPv4 via DHCP, but evidently reserves it so it hasn't changed in two years. But once they roll out IPv6, they might change how their DHCP (4 and 6) works.

  • Hi   Are you referring to the below status on GUI for your existing added DynDNS?

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'Verify Answer' link.

  • Yes, that status. In my firewall the first three fields are blank and the fourth is "N/A". In the past (with Google), it would update regularly, and I could see the update in a log -- can't remember which one.

    I have filled in the API information for my Cloudflare, but since it apparently doesn't fire off Cloudflare DDNS unless my public IP changes, I cannot tell if the Cloudflare info is in fact correct. I'd like to force it to update. (Again, in the past, Google updated every 5 or 10 minutes, I think, so I could check this status and see.)

  • Hi   Thank you for confirmation on it, one such investigation is ongoing internally with ID NC-135613, I would suggest opening a Support case for the same to confirm it further internally, once the support case is open please share the case ID for reference to review its progress and to add internal note over it.

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'Verify Answer' link.

  • HI,

    I reviewed the logviewer for DDNS updates and found that updates occur at 22:58:04 with two entries every day.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • What I've heard from Sophos so far: They have a sample Google DNS account and were able to test DDNS with Google and it works as I remember. They don't have a sample Cloudflare DNS account, though. Unfortunately, the SFOS Cloudflare agent wants the account's Master Key (which gives total access/control over your Cloudflare account) rather than using the specialized DNS API Key, so I wasn't comfortable giving them this key to test on their system.

    What DDNS service are you using? Google, Cloudflare, other?

  • Hi Wayne,

    I am running DynDns.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply Children
No Data