<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Ipsec on Sysadmin Tales</title>
    <link>https://blog.ssb-tech.net/tags/ipsec/</link>
    <description>Recent content in Ipsec on Sysadmin Tales</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:39:10 -0400</lastBuildDate>
    <atom:link href="https://blog.ssb-tech.net/tags/ipsec/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>PSA: Unifi IPSec site-to-site tunnels and DHCP</title>
      <link>https://blog.ssb-tech.net/posts/unifi-ipsec-and-dhcp/</link>
      <pubDate>Tue, 01 Apr 2025 13:09:28 -0400</pubDate>
      <guid>https://blog.ssb-tech.net/posts/unifi-ipsec-and-dhcp/</guid>
      <description>&lt;p&gt;Bit of a PSA of sorts, as this is the second time that I have run into this particular issue.&lt;/p&gt;&#xA;&lt;p&gt;Scenario: You had a Unifi gateway such as a UDM Pro with a static IP address. You switched your WAN IP from static to dynamic, for whatever reason. (In my case it was a different ISP that doesn&amp;rsquo;t hand out actual static IPs, only DHCP reservations.)&lt;/p&gt;&#xA;&lt;p&gt;You may find that the router holds onto that old IP, and if you&amp;rsquo;re like me, you&amp;rsquo;ll be confused as hell.&lt;/p&gt;&#xA;&lt;p&gt;The cause is your IPSec site-to-site tunnel.&lt;/p&gt;&#xA;&lt;p&gt;You&amp;rsquo;ll need to make note of any settings it had (Pre-shared keys, remote endpoints, remote subnets, etc), delete the tunnel completely, and then once you&amp;rsquo;ve successfully gotten your new IP from DHCP, recreate the tunnel from scratch.&lt;/p&gt;&#xA;&lt;p&gt;Once you remove the tunnel, you should get an IP from DHCP almost immediately.&lt;/p&gt;&#xA;</description>
    </item>
  </channel>
</rss>
