<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD and DDNS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153425#M1114746</link>
    <description>&lt;LI-CODE lang="markup"&gt;Previously I had a DDNS client configured on a Synology NAS and that worked without any issues&lt;/LI-CODE&gt;
&lt;P&gt;is this with same FTD ?&lt;/P&gt;
&lt;P&gt;but I have problem getting it to work on the FTD.&amp;nbsp; - is this problem after upgrade to 7.4 or never worked ?&lt;/P&gt;
&lt;P&gt;how are you managing FTD using FDM or FTD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jul 2024 13:18:00 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2024-07-30T13:18:00Z</dc:date>
    <item>
      <title>FTD and DDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153386#M1114745</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm trying to get DDNS to work on a FTD 7.4, but without any luck so far.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Previously I had a DDNS client configured on a Synology NAS and that worked without any issues, but I have problem getting it to work on the FTD.&lt;/P&gt;
&lt;P&gt;When enable debug DDNS, I can see the following:&lt;/P&gt;
&lt;P&gt;#debug ddns&lt;BR /&gt;DDNS update request = /xyz?hostname=vpn.mydomain.se&amp;amp;myip=78.71.10.10&lt;BR /&gt;URL request = &lt;A href="https://dyndns.loopia.se/xyz?hostname=" target="_blank" rel="noopener"&gt;https://dyndns.loopia.se/xyz?hostname=&lt;/A&gt;&amp;lt;h&amp;gt;&amp;amp;myip=&amp;lt;a&amp;gt;&lt;BR /&gt;Buf request = text/plain; charset=UTF-8&lt;BR /&gt;Host: dyndns.loopia.se&lt;BR /&gt;Authorization: Basic ZmlyZXBvd2VyLnNlOjNxd6Fv3Sdjb2s=&lt;BR /&gt;User-Agent: Cisco/1.0&lt;/P&gt;
&lt;P&gt;A "show ddns update interface outside" gives this output:&lt;/P&gt;
&lt;P&gt;show ddns update interface outside&lt;/P&gt;
&lt;P&gt;Dynamic DNS Update on outside:&lt;BR /&gt;Update Method Name Update Destination&lt;BR /&gt;WEB not available&lt;/P&gt;
&lt;P&gt;Last Update attempted on 12:13:05.337 UTC Tue Jul 30 2024 &lt;BR /&gt;Status : Failed&lt;BR /&gt;Reason : Could not establish a connection to the server&lt;/P&gt;
&lt;P&gt;The DDNS config looks like this and I have also downloaded and import the CA certificate from the DDNS provider according to the config guide.&lt;/P&gt;
&lt;P&gt;interface Ethernet1/1&lt;BR /&gt;no switchport&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ddns update hostname vpn.mydomain.se&lt;BR /&gt;ddns update WEB&lt;BR /&gt;dhcp client update dns server both&lt;BR /&gt;ip address dhcp setroute &lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ddns update method WEB&lt;BR /&gt;web update-url &lt;A href="https://username:password@dyndns.loopia.se/xyz?hostname=" target="_blank" rel="noopener"&gt;https://username:password@dyndns.loopia.se/xyz?hostname=&lt;/A&gt;&amp;lt;h&amp;gt;&amp;amp;myip=&amp;lt;a&amp;gt;&lt;BR /&gt;interval maximum 0 0 5 0&lt;/P&gt;
&lt;P&gt;Anyone know what can be the issue? I can ping the DDNS server without any problem, so I dont think it's DNS related.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 07:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153386#M1114745</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2024-07-31T07:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and DDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153425#M1114746</link>
      <description>&lt;LI-CODE lang="markup"&gt;Previously I had a DDNS client configured on a Synology NAS and that worked without any issues&lt;/LI-CODE&gt;
&lt;P&gt;is this with same FTD ?&lt;/P&gt;
&lt;P&gt;but I have problem getting it to work on the FTD.&amp;nbsp; - is this problem after upgrade to 7.4 or never worked ?&lt;/P&gt;
&lt;P&gt;how are you managing FTD using FDM or FTD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 13:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153425#M1114746</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-07-30T13:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and DDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153429#M1114747</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 14:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153429#M1114747</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-30T14:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and DDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153436#M1114748</link>
      <description>&lt;P&gt;This was the first time I tried to set it up with FTD. Before I had it configured on a Synology NAS behind the FTD.&lt;/P&gt;
&lt;P&gt;I followed the guide here her:&amp;nbsp;&lt;A href="http://&amp;nbsp;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/interfaces-settings-dhcp-ddns.html" target="_self"&gt;&amp;nbsp;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/interfaces-settings-dhcp-ddns.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FTD is managed by FMC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 13:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153436#M1114748</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2024-07-30T13:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and DDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153439#M1114749</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Are you sure about that? WEB method is mention in the configuration guide and I can select it in FMC.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="155112.jpg" style="width: 840px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/224814i84C3D923F8BC8383/image-size/large?v=v2&amp;amp;px=999" role="button" title="155112.jpg" alt="155112.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 13:54:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153439#M1114749</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2024-07-30T13:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and DDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153440#M1114750</link>
      <description>&lt;P&gt;Fmc you use 7.x ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 13:59:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153440#M1114750</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-30T13:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and DDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153442#M1114751</link>
      <description>&lt;P&gt;FMC and FTD are both on 7.4&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 14:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153442#M1114751</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2024-07-30T14:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and DDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153787#M1114765</link>
      <description>&lt;P&gt;Regarding DNS, just to be sure, when you try to ping the DDNS server (dyndns.loopia.se), you're doing so from the FTD appliance?&lt;BR /&gt;This could also be a certificate issue, if the appliance trusts the certificate from the dyndns server?&lt;/P&gt;
&lt;P&gt;In order to check if connectivity is being made and successful, you could run a packet capture on the outside interface and matching all traffic to the IP address that dyndns.loopia.se resolves to, and verify if the FTD appliance is trying to make a connection and if three-way-handshake is successful.&lt;BR /&gt;This way you can rule out if it's a connectivity/DNS issue or not.&lt;/P&gt;
&lt;P&gt;So if you can see the connection being made, I would verify if the FTD has a trustpoint for the CA of the DDNS server (step 9 in the guide you referenced), and debug SSL while verifying.&lt;/P&gt;
&lt;P&gt;Another thing I want to point out, while getting the debug output is appreciated in your original post, the Authorization header includes a base64 encoded user/pass, which is reversible (it's an encoding technique, not encryption). If these are your credentials for this service I highly recommend you change them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 00:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153787#M1114765</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2024-07-31T00:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and DDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153888#M1114767</link>
      <description>&lt;P&gt;Thanks, It was indeed the certificate that caused the issue. I just received a new CA cert from Loopia and now everything looks good.&lt;/P&gt;
&lt;P&gt;Update URL request = &lt;A href="https://dyndns.loopia.se/xyz?hostname=&amp;lt;h&amp;gt;&amp;amp;myip=&amp;lt;a&amp;gt;" target="_blank"&gt;https://dyndns.loopia.se/xyz?hostname=&amp;lt;h&amp;gt;&amp;amp;myip=&amp;lt;a&amp;gt;&lt;/A&gt;&lt;BR /&gt;Successfuly updated the DDNS sever with current IP addresses&lt;BR /&gt;DDNS: Another update completed, outstanding = 0&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 07:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-ddns/m-p/5153888#M1114767</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2024-07-31T07:14:14Z</dc:date>
    </item>
  </channel>
</rss>

