Docs › Dynamic DNS

Dynamic DNS on OPNsense

Install the os-ddclient plugin under System ▸ Firmware ▸ Plugins. The legacy os-dyndns plugin was removed in 23.7. OPNsense sends real HTTP Basic authentication.

Where the setting lives

Services ▸ Dynamic DNS (after installing os-ddclient)

Configuration

OPNsense: Services ▸ Dynamic DNS
Service:   Custom
Protocol:  DynDNS 2
Server:    api.home.network
Force SSL: yes
Hostname:  nas.alice.home.network
Username:  alice
Password:  <your update password>

Replace alice with your label and <your update password> with the password from the setup wizard. The username is your label, never your email address.

Worth knowing. Server takes the hostname only. No scheme and no path: both backends append /nic/update themselves, so pasting a full URL produces https://https://api.home.network/nic/update/nic/update. There is no Parameters field, and %h or %i belong to UniFi rather than here. Tick Force SSL so the request goes over HTTPS.

Check it worked

verify
# confirm the record moved
dig +short nas.alice.home.network @ns1.home.network

# the update endpoint answers with the dyndns2 status word
curl -u 'alice:<your update password>' \
  'https://api.home.network/nic/update?hostname=nas.alice.home.network&myip=auto'
good 203.0.113.7

good means the record changed, nochg means it was already correct. Both are success. badauth means the username or password is wrong, and 911 means the fault is at our end, so retry rather than reconfigure.

Still not resolving at home?

If the name answers from ns1.home.network but not from your own resolver, the resolver is stripping the private address as rebind protection. Fix it for your resolver.

← All documentation