This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG’s Free Dynamic DNS error on IP change

I have an XG Home installed at my home. So far it has been working fine except for a small problem. I have a dynamic IP from the ISP, so i configured the XG to use the Sophos dynamic DNS. The registration worked fine at first - i was able to register xxx.myfirewall.co and get the XG reachable from the remote sites through DNS resolution.  Because of a scheduled XG reboot, I ended up getting a new IP from the ISP.  Instead of XG updating the xxx.myfirewall.co to point to the new IP, i kept seeing an error on the XG - DDNS update for host xxx.myfirewall.co was Failed. Last Updated with IP: xx.xx.xx.xx. Failure Reason: Hostname already taken!

I ended up removing the DNS mapping and tried to create a new one pointing the new IP to the old domain xxx.myfirewall.co. This gives me an error that the Hostname is already taken, please use another hostname. When I do a nslookup to the domain, it points to the old IP i had. 

I am able to create a new DNS mapping for a new domain name and that works. But this is a hassle since i will have to edit the SSL VPN profiles for users and map them to the new domain.

My questions are

1. How long will the old DNS entry be alive ? Isn't there a heartbeat to check that the client's IP has changed

2. I read through the XG documentation and it says that the IP refresh should happen automatically. The DNS  server's identify the appliance based on the Serial Number. So why is it not happening for me ? How can i get my old domain back ?



This thread was automatically locked due to age.
Parents
  • Hi AB5g ,

    You may conduct the steps below.

    1. Open Console > option 5>3  for advance Shell

    2. run the command tail -f /log/WINGc.log

    3.Goto DDNS and select edit and save it

     

    Check the logs , you may find the issue there. CHeck the IP at the moment getting resolved .Ping <XXX.myfirewall.co>

  • Thank you for checking this. Here are the logs. It doesn't look like the issue at the XG end. Perhaps something at the Sophos DNS side ?

    On the GUI - the error is - Hostname is already taken, please use another hostname

    May 17 20:45:06.994232 [MSG] process_request: tlv->type: 20 'add_ddns_acc', tlv->length: 32
    May 17 20:45:06.994270 [MSG] already inserted iface 'Port3'
    May 17 20:45:06.994279 [ERR] tlv_add_ddns_acc() aid '1' host 'xxx.myfirewall.co' if 'Port3' ref '1200000' natted '0'
    May 17 20:45:06.994286 [ERR] handle_ddns_async() async ddns request 'xxx.myfirewall.co' pending... state '0'
    May 17 20:45:07.009188 [ERR] handle_ddns_async() async ddns request 'xxx.myfirewall.co' pending... state '3'
    May 17 20:45:07.028028 [MSG] handle_ddns() async ddns request served. 'xxx.myfirewall.co'
    May 17 20:45:07.028080 [ERR] send_ddns_tlv_fail: ddns fail - accountid '0' '3'

    SFVH_SO01_SFOS 17.0.6 MR-6# nslookup
    > xxx.firewall.co
    Domain Name Server# 127.0.0.1
    Domain Name # (null)
    Resolved Address 1# 68.178.213.61
    Total query time # 241.12 msec

    ping xxx.myfirewall.co
    PING xxx.myfirewall.co (xx.xxx.128.192): 56 data bytes

    SFVH_SO01_SFOS 17.0.6 MR-6# service -S | grep dn
    dnsd RUNNING
    fqdnd RUNNING
    SFVH_SO01_SFOS 17.0.6 MR-6#

     

  • Hi AB5g ,

    It seems that is likely the case here, I would recommend you to send me a private message the details

    Serial number (Appliance KEY)

    DDNS name "XXX.myfirewall.co":

    We shall release and let you know when it is done.

Reply Children
  • Hi, I have the same issue ("Hostname already taken!" message in the reason why the DDNS is failing to update) after a backup-restore to a new hardware and device serial (old HW was dying so I moved to a new one). Is there a way to release the current hostname.myfirewall.co myself and add it back to the new device/license or only Sophos (myfirewall.co admin) can do it?

    I suppose I can add a new hostname to the new device, but then I have to replace all my VPN configurations to point to the new hostname which I would like to avoid.

    Thank you in advance.

    BR