Web Host Chat - The UK hosting forum
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Game Servers
Go Back   Web Host Chat > Web Hosting Chat > Networking, Routing and Transit
Reply
 
LinkBack Thread Tools
Old 18th August 2008   #1 (permalink)
Platinum Bad Boy
 
Join Date: Dec 2003
Posts: 533
samtam is on a distinguished road
VPN on Dynamic IP

I have done VPN on statistic IP before with no problem but I am wondering how does it run on dynamic IP..
I know i can use DDNS service to point to the IP but when the IP gets changed will it result in downtime/

Sam
__________________
----------------

Sam Tam
samtam is offline   Reply With Quote
Old 18th August 2008   #2 (permalink)
Platinum Bad Boy
 
Join Date: Jun 2006
Posts: 474
burble is on a distinguished road
A bit. You can get applications for some DDNS services (dyndns for example) that you run on a machine behind the dynamic IP that will keep it updated. The IP shouldn't get changed unless you reconnect, so the only extra downtime you'll have is a longer reconnect time (exact time depending on your DDNS service and how you configure your update software). I've been running a non-critical machine on a dynamic IP with dyndns for several years without any major problems.

Have you contacted the ISP to ask if they'll give you a static IP? Most seem to, at least as a payable upgrade. If not, might be worth moving - I guess it depends on how critical access to the VPN is.
burble is offline   Reply With Quote
Old 18th August 2008   #3 (permalink)
 
markcastle's Avatar
 
Join Date: Aug 2002
Location: London, England
Posts: 3,376
markcastle is on a distinguished road
First question would be... what type of VPN?
PPTP is no problem on a dynamic IP.
Normal IPsec works on a dynamic IP but every time your IP changes you have to edit the config at the remote end to re-establish the link (if you use the IP and not a DDNS name).
Have a look at Mobile IPsec.
I'm not sure about OpenVPN.
__________________
••• Mark Castle ••• Secura Hosting Ltd •••
••• Managed Hosting •••
••• AS29452UK Company Reg No: 04330657VAT Number: 789 2703 81Sales: 0845 123 2632 •••
My views are my own and not those of my company.
markcastle is online now   Reply With Quote
Old 18th August 2008   #4 (permalink)
 
Join Date: Aug 2007
Location: Lincoln, UK
Posts: 1,670
freethought is on a distinguished road
Are both ends going to be on a dynamic IP or will one end (acting as the server) be on a static IP?

Companies like Cisco and Fortinet have IPSec based software clients that can handle coming from dynamic IPs and even being behind NATs (NAT-T/NAT Traversal. These needs to be terminated on a proprietary device made by that company.
I don't know about Cisco, but Fortinet can build tunnels TO a device on a dynamic IP as long as it has DyDNS

I THINK you can use Racoon on Linux as both the software client and the server for a dynamic IPSec VPN but I've never done it myself.

SSL based clients are all the rage these days and can take a lot of the headaches out of configuring VPNs. OpenVPN is an open source SSL VPN client/server that somehow manages to put a lot of the headaches back in.

There are open source L2TP and PPTP packages to act as both the client and the server that don't mind being on dynamic IPs but I have no idea what they are called off hand.
__________________
Freethought Internet Limited
Hosting and communications
Freethought Group Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP.
Xion Internet and Freethought Internet are trading names of Freethought Group Limited.
freethought is online now   Reply With Quote
Old 18th August 2008   #5 (permalink)
Platinum Bad Boy
 
Join Date: Dec 2003
Posts: 533
samtam is on a distinguished road
Well here what I want to do
Location A Switch <--->VPN Server A <--->Internet Cloud<--->VPN Server B<--->Lots of Backup servers(each with a IP from Location A)
So I want to assign the backup servers with the location A IP addresses and make it as it is in Location A. And type of like tunneling the whole thing through.

Of course my concern is if I have to use dynamic IP at the Location B, (Statistic IP is too expensive is location B- talking about silly prices) and their IP can be changed without even reloggin. And therefore I want min. download, that why I am asking whether if anyone has experience on using VPN via dynamic IP and whether there is any downtime during the IP change.
Thanks
Sam
__________________
----------------

Sam Tam
samtam is offline   Reply With Quote
Old 18th August 2008   #6 (permalink)
 
Join Date: Aug 2007
Location: Lincoln, UK
Posts: 1,670
freethought is on a distinguished road
I work from home via a VPN regularly and I've not had any problems so far, but then again NTL changes my IP once in a blue moon...
__________________
Freethought Internet Limited
Hosting and communications
Freethought Group Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP.
Xion Internet and Freethought Internet are trading names of Freethought Group Limited.
freethought is online now   Reply With Quote
Old 19th August 2008   #7 (permalink)
 
BurtyB's Avatar
 
Join Date: Apr 2004
Location: Newark, UK
Posts: 864
BurtyB is an unknown quantity at this point
Quote:
Originally Posted by samtam View Post
Well here what I want to do
Location A Switch <--->VPN Server A <--->Internet Cloud<--->VPN Server B<--->Lots of Backup servers(each with a IP from Location A)
So I want to assign the backup servers with the location A IP addresses and make it as it is in Location A. And type of like tunneling the whole thing through.
If you have a static IP in location A you should be fine using something like OpenVPN which if configured as client in location B, and server in location A will reconnect happily when the IP changes [i.e. when the VPN drops]. You can also add rules to add/remove routes when the VPN is up/down to allow access to the IPs over the VPN.

ChrisB.
__________________
Chris Burton Othello Technology Systems Ltd AS29527 Company#03894981 VAT#GB-782561410 Tel:0871 277 6875
consultancy domains email forwarding resellers ecommerce colo rackspace ip transit secondary mx/dns dedicated servers backup/DR
* OthelloHosts.net Linux and Windows High-Availability Professional Email / Web / Secure Hosting
* OthelloVPS.net Managed Xen Enterprise Virtual Private Servers and Dedicated Servers
# Currently buying web hosts and domain resellers - www.hostacquisitions.co.uk
Views expressed in this post are my own and not Othello Technology Systems Ltd.
BurtyB is offline   Reply With Quote
Old 28th August 2008   #8 (permalink)
 
Join Date: Sep 2005
Location: Leeds
Posts: 1,635
PeteK is on a distinguished road
The whole thing doesn't sound too promising if they are backup servers at location B to me. Surely if the session drops, the backups will terminate, be they actual disk to disk, or rsync or a client server and when the vpn re-establishes later when dyndns or whatever has sorted its life out, you are well stuffed.
Surely you are going to have to have static IPs if this is a "business" solution?
__________________
CCS Leeds Ltd

Company reg: 03507910 VAT reg: GB 698 2027 05
------------------------------------------------
10Meg UK Leased Line only £550 per month
100Meg Leased Line Broadband £1795 per month
------------------------------------------------
PeteK is offline   Reply With Quote
Old 29th August 2008   #9 (permalink)
 
Join Date: Mar 2002
Location: London, United Kingdom
Age: 39
Posts: 4,855
othellotech is on a distinguished road
Quote:
Originally Posted by PeteK View Post
Surely you are going to have to have static IPs if this is a "business" solution?
Static IP's cost money, and this is Sam we're talking to ...
__________________
Rob Golding Othello Technology Systems Ltd AS29527 Company#03894981 VAT#GB-782561410 Tel:0871 277 6875
consultancy domains email forwarding resellers ecommerce colo rackspace ip transit secondary mx/dns dedicated servers backup/DR
* OthelloHosts.net Linux and Windows Clustered High-Availability Professional Email / Web / Secure Hosting
* OthelloVPS.net Managed Xen Enterprise Virtual Private Servers and Dedicated Servers
# Currently buying web hosts and domain resellers - www.hostacquisitions.co.uk
othellotech is offline   Reply With Quote
Old 29th August 2008   #10 (permalink)
 
BurtyB's Avatar
 
Join Date: Apr 2004
Location: Newark, UK
Posts: 864
BurtyB is an unknown quantity at this point
Quote:
Originally Posted by PeteK View Post
The whole thing doesn't sound too promising if they are backup servers at location B to me. Surely if the session drops, the backups will terminate, be they actual disk to disk, or rsync or a client server and when the vpn re-establishes later when dyndns or whatever has sorted its life out, you are well stuffed.
This isn't how it works for me, when a VPN drops and reconnects the packets get queued up and retrys for a while. If during this time it reconnects all is well but if it takes longer and things timeout then I just check the error code on rsync (or whatever your using) and try a few times again.

ChrisB.
__________________
Chris Burton Othello Technology Systems Ltd AS29527 Company#03894981 VAT#GB-782561410 Tel:0871 277 6875
consultancy domains email forwarding resellers ecommerce colo rackspace ip transit secondary mx/dns dedicated servers backup/DR
* OthelloHosts.net Linux and Windows High-Availability Professional Email / Web / Secure Hosting
* OthelloVPS.net Managed Xen Enterprise Virtual Private Servers and Dedicated Servers
# Currently buying web hosts and domain resellers - www.hostacquisitions.co.uk
Views expressed in this post are my own and not Othello Technology Systems Ltd.
BurtyB is offline   Reply With Quote
Old 29th August 2008   #11 (permalink)
 
Join Date: Aug 2007
Location: Lincoln, UK
Posts: 1,670
freethought is on a distinguished road
Quote:
Originally Posted by BurtyB View Post
This isn't how it works for me, when a VPN drops and reconnects the packets get queued up and retrys for a while. If during this time it reconnects all is well but if it takes longer and things timeout then I just check the error code on rsync (or whatever your using) and try a few times again.

ChrisB.
Same here, I've seen ping responses of close to a minute for the first packet due to queuing while a VPN tries to re-establish to a particularly busy node.
__________________
Freethought Internet Limited
Hosting and communications
Freethought Group Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP.
Xion Internet and Freethought Internet are trading names of Freethought Group Limited.
freethought is online now   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


User Information
»REGISTER NOW!
Networking, Routing and Transit Routers, Switches, Layer 2, Layer 3, BGP or Wireless - Chat about it here


Quick forum search
 

Special Hosting Offers

Hot Stuff


Powered by vBulletin® Version 3.8.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0