Re: VPNs with DHCP endpoints? OT?



George <george@xxxxxxxxxxxxxx> hath wroth:

Jeff Liebermann wrote:
Dynamic DNS service. I'm up to about 14 entries on dyndns.com for
some of my customers. There are lots of other dynamic DNS services.
The VPN routers I've tinkered with do NOT require a numeric IP address
and will accept a FQDN (fully qualified domain name).

Every time I have ever setup dynamic DNS with them they disable it
within a few months. This is using their client. I get an email that the
account is about to expire and then they turn it off.

What sort of results do you see? Do you have some sort of paid account
that was previously offered? I see now they only offer the free service.

The first 5 dynamic DNS names were free. I now pay something like
$10/year for the rest of the name.

I accidentally mistyped an account name which of course never got
updated by the client. After about 2 weeks, I get a notice that it's
about to expire. Apparently if the updates are no sufficiently often,
it assume the account is comatose and it expired. I've let one
account expire and it literally disappeared from the settings page.
That was with the free service.

I just checked my list of names under My Services and found that one
client hasn't been updated since April 2005. That's when I changed
the router and probably screwed up the DDNS setup. (Oops). It's
still on the setup page and still active. Another hasn't been updated
since Nov 2005, when the customer punched the reset button on their
router, and that's still there. I guess they don't expire if you pay
for the service. Most of the others are less than a month old.

I use a mixture of their client software and the built in dyndns.com
client in some routers. I've had good luck with current Netgear and
Linksys routers. I've had miserable luck with older routers (i.e.
DI-514, RT-314). Basically, some built in clients are broken. What
I've noticed is that those that report success or failure to a log
file seem to work. Those without logging seem to screw up, probably
because the client doesn't check for success or failure and just
broadcasts an update.

On the client software, I've had some entertainment value caused by
ZoneAlarm and Norton Internet Security. These check for permission
for an outgoing program to send a packet to the internet. The dyndns
client is suppose to be automatically configured in these personal
firewalls when first run. For some unknown reason, it seems to either
delay the setup or do it all wrong. I've had to delete the dyndns
record from both ZoneAlarm and NIS, re-authorize the client, and then
it works. Other than a few versions of the client that were
apparently buggy (would die every few days), the software client works
just fine for me on about 6 machines.

If you're really paranoid, put the dyndns client on two computers and
have them both do updates to either the same account or to different
accounts. One or the other should work. I have two names for some of
my critical servers (weather stations on mountain tops) that I can't
afford to have fail. The catch is do NOT pound on the dyndns servers
with updates too often. They treat that as abuse and somehow block
the source IP.

If you login to your account on dyndns.com and check the "last
updates" column on the setup page, it might give a clue as to what's
happening.

--
Jeff Liebermann jeffl@xxxxxxxxxxxxxxxxxxxxxx
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558
.



Relevant Pages

  • Re: Branch Office MVBASE network access
    ... We use Watchguard routers for VPN between sites, ... Accuterm or the bundled thin client ...
    (comp.databases.pick)
  • Re: How to show messagebox in other computer in a network?
    ... If you mean the TCP/IP send function, ... A "maislot client" opens a file called ... and it is designated as a "mailslot server" (your servers are clients and your clients are ... across routers and especially if the routers are going out to the general internet, ...
    (microsoft.public.vc.mfc)
  • Re: Unable to make VPN connection to ISA 2006 Standard
    ... routers in question are blocking this. ... This weekend I am going to remove ISA and see if I can make a PPTP ... What I'm really trying to do here is a site to site VPN. ... Thanks for your pointer about the AUtomatic client setting trying LT2P - I ...
    (microsoft.public.isa.vpn)
  • Re: Unable to make VPN connection to ISA 2006 Standard
    ... routers in question are blocking this. ... This weekend I am going to remove ISA and see if I can make a PPTP ... What I'm really trying to do here is a site to site VPN. ... Thanks for your pointer about the AUtomatic client setting trying LT2P - I ...
    (microsoft.public.isa.vpn)
  • Re: Pushing security patches and update to clients
    ... >How can I push updates out to the clients without having to logg on as an adminstrator localy at the client workstation? ... Write a script to install the updates. ... Call the install script from the domain installer account login script. ...
    (microsoft.public.windowsxp.network_web)