Re: IPsec config with dynamic IP.

2016-02-19 Thread Christopher Sean Hilton
On Fri, Feb 19, 2016 at 11:36:04AM +, Stuart Henderson wrote: > On 2016-02-18, Christopher Sean Hilton wrote: > > My box cannot resolve the name "ike-v1.example.com" until > > after isc_named is started which happens way late in the bootup > > That seems like a misconfiguration - ap

Re: IPsec config with dynamic IP.

2016-02-19 Thread Stuart Henderson
On 2016-02-18, Christopher Sean Hilton wrote: > My box cannot resolve the name "ike-v1.example.com" until > after isc_named is started which happens way late in the bootup That seems like a misconfiguration - apart from this issue, what if BIND crashes or you need to update it? can't yo

IPsec config with dynamic IP.

2016-02-18 Thread Christopher Sean Hilton
I have an IPSec VPN endpoint running on OpenBSD on a cable modem. Technically it has a dynamic IP but in practice the IP only changes about once every 3 ~ 5 years. I run ddclient on the OpenBSD box to maintain the dns name of the box so I can find it and that's working well. My ipsec configuration