Nobody uses dynamic IP with site2site IPSEC VPN?
Quote from: Ricardo on November 22, 2020, 07:31:54 pmNobody uses dynamic IP with site2site IPSEC VPN?Nope. At least I don't support any such configuration and would strongly argue to get fixed IP addresses to any customer. And I have built quite a number of IPsec based VPNs in my life.Doesn't help - sorry.Patrick
Or I need to workaround the situation with custom scripts and service restarts?
I had IPsec tunnels to locations with IPs changing every night and I didn't have to restart IPsec every morning. But from time to time the tunnel didn't come up after connection lost (not necessarily only a change in IP).With wireguard you have the situation that dynDNS name is only resolved once, but not if handshake fails.
Yepp, both sides dynamic, but not changing IP at the same time, normally.It's years ago, I switched to openVPN, site-to-site. Very stable with dynDNS. But Wireguard might be more secure?
Quote from: Ricardo on November 23, 2020, 11:09:52 amOr I need to workaround the situation with custom scripts and service restarts?I would go for this one. As far as I can see the IP for a FQDN is only resolved once during startup.So you need a script which checks if a tunnel is running and if not it should restart it.Maybe this thread is a help:https://forum.opnsense.org/index.php?topic=13543.0
Quote from: chemlud on November 23, 2020, 02:54:26 pmYepp, both sides dynamic, but not changing IP at the same time, normally.It's years ago, I switched to openVPN, site-to-site. Very stable with dynDNS. But Wireguard might be more secure?If choosing the right ciphers and algorithms OpenVPN and IPsec are very secure. WireGuard is not yet production ready so I would be careful to call it more secure.
Quote from: Gauss23 on November 23, 2020, 12:19:17 pmQuote from: Ricardo on November 23, 2020, 11:09:52 amOr I need to workaround the situation with custom scripts and service restarts?I would go for this one. As far as I can see the IP for a FQDN is only resolved once during startup.So you need a script which checks if a tunnel is running and if not it should restart it.Maybe this thread is a help:https://forum.opnsense.org/index.php?topic=13543.0Much appreciated, I will see the next time if it helps!