InfraNestInfraNest

Automation

Your IP changes. Nothing else has to.

Your router tells InfraNest its new address, and everything that depends on it follows — the A and AAAA records so your name keeps resolving, and the cloud firewall rules so you are not locked out of your own servers. There is nothing to install: it speaks the dynamic DNS your router already has built in.

Free plan · No credit card · Works with the router you already have

  • DNS records and firewall rules, one address
  • Nothing to install on your router
  • Only your entry in the rule is touched
  • Told when it stops, before it costs you
Home office — Utrecht
Current IP

IPv4

84.24.117.62

IPv6

2a02:a44f:12c3:1:9ad3:74be:5f01:2c18

Network

Utrecht · KPN B.V.

Last seen

1m

When it checks in, these update

vpn (A)northwind-bastion

Safety

Recent changes
IPv484.24.109.784.24.117.621m
IPv62a02:a44f:12c3:1:6c81:2f0a:bb14:9d332a02:a44f:12c3:1:9ad3:74be:5f01:2c1819h
IPv484.24.98.21184.24.109.79d
IPv484.24.98.21161d

Keep A (IPv4) and AAAA (IPv6) records pointed at this IP. Pick an existing record, or create a new one here.

vpn.northwind.comA
+ Add DNS record

Whitelist this IP in a firewall rule (e.g. allow SSH from your home IP). Only your entry is updated — other IPs in the rule are left untouched. It follows the IP your client reports (public addresses only), and every change is alerted.

A firewall target changes who can reach your servers (e.g. SSH). Check the rule and IP version carefully — you are responsible for the result; InfraNest accepts no liability for lockouts or exposure.

northwind-bastionin|tcp|2284.24.117.62/32
+ Add firewall rule

Your router tells InfraNest what your address is. Put the details below into your router’s Dynamic DNS settings, and everything you’ve linked follows it automatically.

Server

Just the address — no https:// in front

dyn.infranest.io

Hostname

Any name your router accepts — we update whatever you linked below

vpn.northwind.com

Username

Identifies this Dynamic IP. It is not a password

dyn-4m2qhv7k

Password

Treat this like a password — only your router needs it

••••••••••••••••••••••••

Your router reached us 1m and everything worked.

Works with your DNS providers

HetznerCloudflareTransIPGoDaddyIONOSNamecheapAmazon AWSDynadotDigitalOceanOVHcloudPorkbunOpenProvider

See all 30 integrations →

Not just DNS — the firewall rule as well

Most dynamic-DNS tools stop at the name. But if you allow SSH from your home IP, that allow-list is the thing that actually locks you out when your provider hands you a new address on a Sunday morning. InfraNest updates both from the same check-in. And it does it surgically: it changes the one entry it wrote and leaves every other IP in that rule exactly as it was, because a tool that rewrote your whole allow-list would be a security incident rather than a convenience.

  • Only the entry we wrote is ever changed — every other IP in the rule is left alone
  • The live rule is read back from your provider before every write, so a change you made in their console is not silently reverted
  • A firewall only ever follows the address you genuinely connected from — the reported ?ipv4 override that DNS honours is ignored here, because a query parameter must not be able to open a port
  • Always a single host route, /32 or /128, never a range
  • Private, reserved and carrier-grade NAT addresses are never written anywhere

You find out when it stops — that is the whole point

This is the part the category gets wrong. A dynamic-DNS updater that quietly stopped looks exactly like one that is working, right up until your name points at an address your provider has since given to somebody else. So InfraNest treats silence as news. Two days without a check-in and the row turns amber and you are told. And when a push fails, you are told what kind of failure it was — because “the provider refused it”, “that address is unreachable” and “the rule is gone” are three different problems that used to read as one.

  • Two days of silence turns the row amber and sends one alert — cleared by any check-in, including a “nothing changed”
  • What your provider actually accepted is tracked separately from what we wrote, and retried on every check-in until the two agree
  • A firewall rule that lost its handle is the loudest alert in the module: the entry we last wrote is still open, on an address that may no longer be yours
  • A DNS target that could never publish is refused when you create it, instead of reporting success forever
  • One alert per problem, so the timestamp reads as “broken since” rather than arriving all over again every few minutes

Nothing to install — your router already speaks it

There is no agent and no daemon. InfraNest speaks dyndns2, the same protocol consumer routers and ddclient have implemented for twenty years, so your router is the client. Pick your device and the page shows the exact boxes that device asks for, filled in. And because routers do not send the URL you gave them — they keep the host and append a path of their own — six different aliases are accepted, so whatever yours appends still lands.

  • Speaks dyndns2, which your router, OPNsense, pfSense or ddclient already implements
  • Presets for FRITZ!Box, UniFi, Synology, ddclient, the command line and most other routers
  • The exact fields your device asks for, with its own placeholders left intact
  • Six URL aliases, so whichever path your router appends, the update still arrives
  • Works equally from a cron line or a script — it is one HTTPS call
Home office — Utrecht
Setup

Which device are you setting up?

Set the service to “Custom” and fill in the boxes below. Works on OPNsense, pfSense, ASUS, MikroTik and most others. Step-by-step guide

What to type into your router

Most routers ask for these under “Dynamic DNS”, with the service set to “Custom”. Copy each value into the box with the matching name.

Server

Just the address — no https:// in front

dyn.infranest.io

Hostname

Any name your router accepts — we update whatever you linked below

vpn.northwind.com

Username

Identifies this Dynamic IP. It is not a password

dyn-4m2qhv7k

Password

Treat this like a password — only your router needs it

••••••••••••••••••••

Under Internet › Permit Access › DynDNS, choose “Custom”. Paste the update address, then fill in the other boxes. Step-by-step guide

What to type into your router

Most routers ask for these under “Dynamic DNS”, with the service set to “Custom”. Copy each value into the box with the matching name.

Update URL

Paste the whole address, exactly as shown

https://dyn.infranest.io/••••••••••••••••••••?ipv4=<ipaddr>&ipv6=<ip6addr>

Hostname

Any name your router accepts — we update whatever you linked below

vpn.northwind.com

Username

Identifies this Dynamic IP. It is not a password

dyn-4m2qhv7k

Password

Treat this like a password — only your router needs it

••••••••••••••••••••

Under Internet › Dynamic DNS, choose service “Custom”. The Server box takes the address and path together. Step-by-step guide

What to type into your router

Most routers ask for these under “Dynamic DNS”, with the service set to “Custom”. Copy each value into the box with the matching name.

Server

Just the address — no https:// in front

dyn.infranest.io/nic/update?hostname=%h&myip=%i

Hostname

Any name your router accepts — we update whatever you linked below

vpn.northwind.com

Username

Identifies this Dynamic IP. It is not a password

dyn-4m2qhv7k

Password

Treat this like a password — only your router needs it

••••••••••••••••••••

In DSM, Control Panel › External Access › DDNS › Customize provider. Paste the query URL, then add your details. Step-by-step guide

What to type into your router

Most routers ask for these under “Dynamic DNS”, with the service set to “Custom”. Copy each value into the box with the matching name.

Query URL

Paste the whole address, exactly as shown

https://dyn.infranest.io/nic/update?hostname=__HOSTNAME__&myip=__IP__

Hostname

Any name your router accepts — we update whatever you linked below

vpn.northwind.com

Username

Identifies this Dynamic IP. It is not a password

dyn-4m2qhv7k

Password

Treat this like a password — only your router needs it

••••••••••••••••••••

Add this to /etc/ddclient.conf. Anything that speaks dyndns2 works the same way. Step-by-step guide

Configuration to copy

Paste this into the config file or run it as-is. It already contains your details.

protocol=dyndns2
server=dyn.infranest.io
ssl=yes
login=dyn-4m2qhv7k
password='••••••••••••••••••••'
vpn.northwind.com

Run it from a cron job every few minutes, or from a script when your connection comes up. Step-by-step guide

Configuration to copy

Paste this into the config file or run it as-is. It already contains your details.

curl -sS -u 'dyn-4m2qhv7k:••••••••••••••••••••' 'https://dyn.infranest.io/'

Your router reached us 1m and everything worked. 84.24.117.62 · FRITZ!Box 7590

Everything else it handles

The parts that are only interesting when you need them.

Attach it from where you already are

The same “Track with a Dynamic IP” option appears in the DNS record editor and the firewall rule editor, not only on this page. One source can drive many of both — a home connection updating three records and two firewall rules at once.

Where the connection came from

Every check-in resolves the address offline to a country, a city and the network it belongs to, so “is this still my office line?” is answerable at a glance rather than by pasting an IP into a lookup.

A flag when it moves to a datacentre

A source that is supposed to be a home or office line but arrives from a hosting or VPN network is usually a misconfigured or tunnelled client. That flag is also an automation condition, paired with a built-in action that closes the firewall access it granted.

Fail closed when it goes quiet

Switch it on and a source that stops reporting for about a week has its firewall openings removed and those targets disabled — so an abandoned or leaked token cannot leave a port open forever. The warning arrives an hour before, never after.

The token is treated as a password

Stored hashed, because the update endpoint is public by design. Revealing it again is a deliberate, re-authenticated and audited action, and you can rotate it whenever you like.

A username you can actually diagnose with

Every source carries a published username separate from the secret, so a failed login can be traced to a source. A wrong password against a real username fails exactly as a fake one does, so the endpoint cannot be used to discover which sources exist.

Alerts, webhooks and automations

Change, silence and broken-target alerts through your normal channels — email, Slack, Telegram or a webhook — plus an outbound dynamic_ip.changed event, and org-wide defaults so new sources start with the policy you want.

A history you can read

Every applied change is kept per source, old address to new, and written to the audit log alongside everything else.

Watch your own connection check in

Create a source and paste four values into your router. Nothing is updated until you link a record or a rule to it.

A free dynamic-DNS updater vs InfraNest

The difference between a name that still resolves and knowing whether it does.

A free updater

  • The name quietly points at an address somebody else now holds
  • DNS only — the firewall allow-list is still yours to remember
  • Edit that allow-list by hand when your provider changes your address on a Sunday
  • No way to tell a working updater from one that stopped a month ago
  • A token you cannot rotate leaves a port open indefinitely

With InfraNest

  • Two days of silence and you are told, before anything depends on it
  • DNS records and cloud firewall rules follow the same check-in
  • The allow-list entry rewrites itself — and only the entry that is yours
  • Three named failures, each with the reason and what to do
  • Fail closed removes the opening after a week, and warns you first

One login, ten modules

Every module is in every plan, Free included — what changes is how much of each you get.

The cost of doing it separately

Buy each piece from a different tool and it adds up fast:

Domain & DNS
~€30
Uptime monitoring
~€29
SSL tracking
~€15
Status page
~€29
Server panel
~€15
Across 4–5 separate tools
€100–150/mo
InfraNest Business — all of it, one login€49/mo

Compare all features →

Frequently asked

What is dynamic DNS, and why do I need it?

Most home and small-office connections do not get a fixed public address. Your provider hands you one and swaps it whenever it likes — often after a reconnect or a router reboot. Anything pointing at the old address then stops working: a name that no longer resolves to your machine, or a firewall rule that no longer lets you in. Dynamic DNS — DDNS — is the fix: something notices the new address and updates whatever depends on it. InfraNest does that for your DNS records and, unlike most DDNS services, for your cloud firewall rules too.

Will it work with my router — FRITZ!Box, UniFi, Synology?

Yes, and with almost anything else. InfraNest speaks dyndns2, the standard nearly every router implements: FRITZ!Box, UniFi, Synology, OPNsense, pfSense, ASUS, MikroTik and most consumer models, plus ddclient and inadyn. Pick your device on the setup screen and it shows the exact boxes that device asks for, already filled in. If yours is not listed, the generic “Custom” preset works — and so does a one-line curl from cron.

Can it update a firewall rule, not just DNS?

Yes, and that is the main reason to use it over a free dynamic-DNS service. Link a cloud firewall rule to a Dynamic IP and the address allowed by that rule follows your connection — useful for an SSH or database rule you want open to yourself and nobody else. Only your entry in the rule changes; every other IP in it is left untouched, and the address written is always a single host route.

What happens if my router stops reporting?

After two days without a check-in the source is marked stale and you get one alert — cleared the moment anything checks in again, including a “nothing changed”, which is what a healthy router sends most of the time. If you have turned on fail closed, a source silent for about a week has its firewall openings removed and those targets disabled, and the earlier warning tells you how many days are left. The two run an hour apart deliberately, so the warning is a warning and never a post-mortem.

Is it safe to let a tool change my firewall?

It is the part we have been most careful with. The live rule is re-read from your provider before every write, so nothing you changed in their console is reverted. Only the entry InfraNest wrote is modified. The address is always a single host route, never a range, and never a private or unroutable one. A firewall follows only the address you genuinely connected from — the reported override that DNS accepts is ignored outright, because a query parameter must not be able to open a port. Enabling a firewall target can require re-authentication if your organisation turns that on.

Does it work behind CGNAT?

Not usefully, and it says so rather than pretending. If your provider puts you behind carrier-grade NAT, the address your router reports is not reachable from the internet, so publishing it would point your name at nothing. InfraNest refuses to write it and tells you why — your provider can usually give you a real public address, often for free, if you ask.

How many Dynamic IPs can I have?

Two on the free plan, twenty-five on Pro and unlimited on Business. Each one can drive as many DNS records and firewall rules as you need, so a single home connection keeping three names and two rules in sync counts as one.

One address, everything follows

Create a source and point your router at it — two are included free.

Free plan · No credit card required · Set up in minutes