Skip to content
WebShield Docs

Dynamic IP (DynDNS)

How to keep a DNS record in WebShield pointed at the changing address of your home server or router.

Home connections usually hand out an address for a while: reboot the router and it is a different one. Dynamic DNS solves that — the device reports its current address and we update the record. We speak the usual dyndns2 protocol, the one Keenetic, MikroTik, ASUS, OpenWrt, ddclient and UniFi already know. For anything else, a single command in cron or Windows Task Scheduler is enough.

The domain has to be delegated to our nameservers.

Router, Linux and Windows walkthroughs — plus what happens to SSH behind the proxy — are in the Home server on a dynamic address guide.

  1. Open Control panel → DNS for the domain.
  2. In the Dynamic IP card click Add hostname and type a short name, for example home.
  3. Copy the token. It is shown once: a lost token cannot be recovered, only replaced.

The A/AAAA records appear after the first update — until then the name does not resolve.

In the router’s DynDNS section pick a custom service (Custom, Other, dyndns2) and fill in:

Field Value
Server / Service dyn.webshield.pro
Username the hostname, for example home.example.com
Password the token you copied

If the firmware asks for a full update URL, the standard one works:

https://dyn.webshield.pro/nic/update?hostname=home.example.com&myip=<IP>

The router contacts us whenever the address changes. HTTPS is required — we do not accept updates over plain HTTP, since the token would travel in the clear.

Command for cron or Windows Task Scheduler

Section titled “Command for cron or Windows Task Scheduler”

If the machine sits behind NAT and does not know its own public address, simply do not send one. We take the address the request came from:

Terminal window
curl -fsS "https://dyn.webshield.pro/update?token=YOUR_TOKEN"

Every 5-10 minutes is plenty:

*/10 * * * * curl -fsS "https://dyn.webshield.pro/update?token=YOUR_TOKEN" >/dev/null

The same command in Windows Task Scheduler:

Terminal window
Invoke-RestMethod "https://dyn.webshield.pro/update?token=YOUR_TOKEN"

OK <address> means the record is up to date, KO <reason> means it is not.

To look up your public address on its own: curl https://dyn.webshield.pro/ip.

Parameter Value
myip / ip an IPv4 or IPv6 address (or both, comma separated)
myipv6 an IPv6 address
hostname the hostname; optional, the token is tied to one name anyway

Address families are independent: an IPv4-only update does not drop the AAAA record.

Only public addresses are accepted. 192.168.*, 10.*, carrier-grade NAT ranges and the like are rejected — they are of no use in public DNS.

Response Meaning
good <address> the address was accepted and written
nochg <address> same address, nothing to change
badauth the token is wrong or missing
nohost the hostname does not match the token, or updates are switched off
dnserr the address does not look like a public IP
911 too many updates, try again later

The limit is 10 address changes per 10 minutes per hostname. Repeats with the same address — which is exactly what a router reboot looks like — do not count against it, so rebooting is free.

A hostname with a dynamic address can be proxied (CDN and protection): visitors reach our edge and we connect to your server at its current address. Your home address stays out of DNS, and on the server itself you can close everything except our addresses. We issue the certificate, so there is no need to expose port 80.

After an address change, the switch takes up to a minute.

  • badauth — the token was copied partially or has been rotated. Issue a new one in the card and put it into the device.
  • nohost — the router points at a different hostname, or the name is switched off in the panel.
  • No record appears — check that the domain is delegated to our nameservers and that the device really reaches dyn.webshield.pro over HTTPS.