Documentation Index

Fetch the complete documentation index at: https://help.nordlayer.com/llms.txt

Use this file to discover all available pages before exploring further.

Setting up site-to-site with a dynamic IP

Prev Next

By default, a NordLayer Sites tunnel expects the remote end (your office router, firewall, or server) to have a static public IP address, which you enter in the Remote IP field when creating a Site.

NordLayer VPN site-to-site configuration showing type, encryption settings, and network options

Not every organization can get one. Static IPs are an added cost with many ISPs, are unavailable on some business broadband and mobile/LTE connections, and are often impractical for smaller branch offices or managed sites.

If your remote location gets a dynamic public IP that changes periodically, you can still build a site-to-site tunnel by entering 0.0.0.0 in the Remote IP field.

How dynamic IP site-to-site works

When you set Remote IP to 0.0.0.0, you tell the NordLayer server not to expect the tunnel from one specific address. Instead, the Site accepts an incoming IPsec connection from any public IP, as long as the peer presents the correct pre-shared key and matching encryption parameters. This is commonly known as a dynamic peer tunnel configuration.

In practice, the difference comes down to who initiates and how the peer is identified:

Static Remote IP Dynamic Remote IP (0.0.0.0)
Remote IP value The fixed public IP of your site 0.0.0.0
Peer identification By IP address plus pre-shared key By pre-shared key and IKE identity only
Who initiates the tunnel Either side Your remote device must always initiate
Effect of an ISP IP change Tunnel breaks until the Site is updated Tunnel re-establishes automatically

Because NordLayer cannot know your current address in advance, it cannot start the negotiation. Your router or firewall must always be the initiator. Once **Phase 1 **and Phase 2 complete, the tunnel behaves exactly like a static-IP tunnel: same routing, same subnets, same encryption, same monitoring in the Control Panel.

Setting up the Site

  1. Log in to the NordLayer Control Panel.
  2. Open the Network section on the left and click Sites.
  3. Click Create Site.
  4. Fill in the standard fields:
    • Site name — a name for this configuration.
    • Dedicated server IP — select the gateway IP that will terminate the tunnel.
    • Type of site-to-site setup — choose On-premises and enter your router or firewall model.
    • Remote ID — provide the unique identity of your remote peer. Note that when the Remote IP is set to 0.0.0.0, the Remote ID cannot be left as %any or 0.0.0.0; it must be explicitly defined to distinguish the peer. If you do not enter a value, it will default to your current public IP.
  5. Under Encryption settings, configure:
    • IKE version — IKEv2. Dynamic-peer tunnels require IKEv2; IKEv1 is not supported for this configuration.
    • Remote IP — enter 0.0.0.0.
    • Subnets — the internal subnet(s) of your local network at the remote site.
    • IKE encryption type and ESP encryption type — we recommend AES256, SHA256, DH Group 14 (modp2048) at a minimum.
  6. Click Create Site and allow some time for the configuration to deploy. You will receive a confirmation email once it is ready.
Note

The Remote IP field currently displays no dedicated option for dynamic addresses, entering 0.0.0.0 manually is the supported method. The Control Panel will display 0.0.0.0 as the Remote IP in the Site details table. A clearer interface for this setting is planned for a future release.

What to expect after an IP change

When your ISP assigns a new public IP, the existing tunnel drops. Your device detects the loss through DPD and re-initiates; the NordLayer server accepts the new address because the Site is not bound to a specific IP. No action is needed in the Control Panel, and the Remote IP column will continue to show 0.0.0.0.

Expect a short interruption, typically under a minute, depending on your DPD timers and how quickly the device reconnects. Sessions traversing the tunnel at that moment may need to be re-established.

Limitations

  • The remote device must initiate. NordLayer cannot initiate a tunnel toward an unknown address, so a tunnel will never come up on its own after a device goes offline until the device reconnects.
  • One dynamic Site per dedicated server IP. Because peers are not distinguished by source address, configure only one 0.0.0.0 Site per dedicated server IP. Additional sites on the same gateway need static Remote IPs.
  • IKEv2 only. IKEv1 does not support this configuration in NordLayer Sites.
  • Carrier-grade NAT (CGNAT). Connections behind CGNAT — common on mobile and some residential ISPs — may fail or reconnect frequently. NAT traversal on UDP 4500 must be permitted end to end.
  • Overlapping subnets. Remote subnets must not overlap with your NordLayer subnet or with other connected sites.

Can't find what you need?

Live chat

Contact our support to solve an issue live.

Chat functionality relies on cookies. By starting the chat, you agree to their use. Learn more in our Cookie Policy.