Dynamic IP (DynDNS)
How to keep a DNS record in WebShield pointed at the changing address of your home server or router.
Home connections usually hand out an address for a while: reboot the router and it is a different one. Dynamic DNS solves that — the device reports its current address and we update the record. We speak the usual dyndns2 protocol, the one Keenetic, MikroTik, ASUS, OpenWrt, ddclient and UniFi already know. For anything else, a single command in cron or Windows Task Scheduler is enough.
The domain has to be delegated to our nameservers.
Router, Linux and Windows walkthroughs — plus what happens to SSH behind the proxy — are in the Home server on a dynamic address guide.
Enable it
Section titled “Enable it”- Open Control panel → DNS for the domain.
- In the Dynamic IP card click Add hostname and type a short name, for
example
home. - Copy the token. It is shown once: a lost token cannot be recovered, only replaced.
The A/AAAA records appear after the first update — until then the name does
not resolve.
Router setup
Section titled “Router setup”In the router’s DynDNS section pick a custom service (Custom, Other,
dyndns2) and fill in:
| Field | Value |
|---|---|
| Server / Service | dyn.webshield.pro |
| Username | the hostname, for example home.example.com |
| Password | the token you copied |
If the firmware asks for a full update URL, the standard one works:
https://dyn.webshield.pro/nic/update?hostname=home.example.com&myip=<IP>The router contacts us whenever the address changes. HTTPS is required — we do not accept updates over plain HTTP, since the token would travel in the clear.
Command for cron or Windows Task Scheduler
Section titled “Command for cron or Windows Task Scheduler”If the machine sits behind NAT and does not know its own public address, simply do not send one. We take the address the request came from:
curl -fsS "https://dyn.webshield.pro/update?token=YOUR_TOKEN"Every 5-10 minutes is plenty:
*/10 * * * * curl -fsS "https://dyn.webshield.pro/update?token=YOUR_TOKEN" >/dev/nullThe same command in Windows Task Scheduler:
Invoke-RestMethod "https://dyn.webshield.pro/update?token=YOUR_TOKEN"OK <address> means the record is up to date, KO <reason> means it is not.
To look up your public address on its own: curl https://dyn.webshield.pro/ip.
Sending the address yourself
Section titled “Sending the address yourself”| Parameter | Value |
|---|---|
myip / ip |
an IPv4 or IPv6 address (or both, comma separated) |
myipv6 |
an IPv6 address |
hostname |
the hostname; optional, the token is tied to one name anyway |
Address families are independent: an IPv4-only update does not drop the AAAA
record.
Only public addresses are accepted. 192.168.*, 10.*, carrier-grade NAT
ranges and the like are rejected — they are of no use in public DNS.
Protocol responses
Section titled “Protocol responses”| Response | Meaning |
|---|---|
good <address> |
the address was accepted and written |
nochg <address> |
same address, nothing to change |
badauth |
the token is wrong or missing |
nohost |
the hostname does not match the token, or updates are switched off |
dnserr |
the address does not look like a public IP |
911 |
too many updates, try again later |
The limit is 10 address changes per 10 minutes per hostname. Repeats with the same address — which is exactly what a router reboot looks like — do not count against it, so rebooting is free.
Dynamic address behind protection
Section titled “Dynamic address behind protection”A hostname with a dynamic address can be proxied (CDN and protection): visitors reach our edge and we connect to your server at its current address. Your home address stays out of DNS, and on the server itself you can close everything except our addresses. We issue the certificate, so there is no need to expose port 80.
After an address change, the switch takes up to a minute.
If something is off
Section titled “If something is off”badauth— the token was copied partially or has been rotated. Issue a new one in the card and put it into the device.nohost— the router points at a different hostname, or the name is switched off in the panel.- No record appears — check that the domain is delegated to our nameservers
and that the device really reaches
dyn.webshield.proover HTTPS.