Candid photograph of a Linux server terminal with a soft olive-green glow against a dark slate background, conveying a calm technical atmosphere.

Step-by-step guides for system administrators — covering command-line basics, web server setup, and preparation material for technical interviews.

Browse Tutorials

Setting Up Dynamic DNS With ddclient on Fedora

A changing public IP address can make a home lab, VPN endpoint, or small server difficult to reach. Dynamic DNS solves this by updating a hostname whenever the address assigned by your internet provider changes. On Fedora, ddclient provides a lightweight way to automate that update from the command line.

This setup is useful across Australia, where NBN connections commonly use dynamic addressing and some providers place residential customers behind carrier-grade NAT. The procedure applies to Fedora Workstation and Fedora Server, although the available settings depend on your DNS provider and router.

Check Your Network And DNS Provider

Start by confirming that your connection has a publicly reachable address. Visit an IP-checking website, then compare the result with the WAN address shown by your router. If the router shows a private address such as 100.64.0.0/10, 10.0.0.0/8, or 192.168.0.0/16, inbound connections may be blocked by CGNAT.

CGNAT is relatively common on Australian residential plans from large and smaller providers, including services sold through Telstra, Optus, and Aussie Broadband. A dynamic DNS record can still update successfully behind CGNAT, but it will not make an internal server reachable from the internet. Ask the provider about a public IPv4 address if external access is required.

Create a hostname with a dynamic DNS service, or use a DNS provider that supports an update API. Record the hostname, username or API token, password, server address, and the DNS zone. If the service supports IPv6, decide whether ddclient should update an AAAA record as well as an A record.

Install ddclient On Fedora

Install the package and inspect its files with dnf:

sudo dnf install ddclient
rpm -ql ddclient | less

The primary configuration is usually /etc/ddclient.conf. Protect it because it contains credentials:

sudo chown root:root /etc/ddclient.conf
sudo chmod 600 /etc/ddclient.conf

Package names and provider templates can change between Fedora releases. Check the installed documentation and provider examples before copying a configuration. A wider collection of Linux configuration references is available through this configuration reference, but the syntax supported by your installed Fedora package should take priority.

Create The Update Configuration

For a provider using the DynDNS2 protocol, a basic configuration can look like this:

daemon=300
syslog=yes
ssl=yes
use=web
web=https://checkip.amazonaws.com/
protocol=dyndns2
server=members.example-dns.com
login=your-account
password='your-api-token'
yourhost.example.com

Replace the server, login, token, and hostname with values from your provider. The daemon=300 setting checks every five minutes, while use=web discovers the public address from an external service rather than reading a private network interface.

Some providers require a token as the password and a literal account name such as token. Others need a provider-specific protocol, endpoint, or zone declaration. Do not place shell variables or unverified options into the file. Use the provider’s current API documentation, and avoid committing this configuration to Git or storing it in a shared home directory.

Enable And Test The Service

Run a foreground test before enabling the service. Depending on the Fedora package version, the command may be:

sudo ddclient -daemon=0 -verbose -noquiet

A successful run should identify the current address and report that the hostname was updated or already matched. If the command reports authentication errors, check the token, hostname, zone, and protocol before changing firewall settings.

Once the manual test works, start the systemd unit:

sudo systemctl enable --now ddclient
sudo systemctl status ddclient
journalctl -u ddclient -f

Useful checks during the first update cycle include:

The DNS result may remain cached briefly according to the record’s TTL. Testing from a mobile connection in Sydney, Melbourne, or another separate network is more useful than testing only from the Fedora host, because local routers may apply split-DNS or hairpin NAT behaviour.

Troubleshoot Updates And Reachability

When a hostname resolves to an old address, inspect the journal and run ddclient verbosely. Confirm that the machine has working outbound DNS and HTTPS access. A correct update cannot compensate for a stale local resolver cache, an incorrect zone, or a provider rejecting the chosen user agent.

If the DNS record is correct but a service remains unreachable, check the Fedora firewall and router port forwarding separately:

sudo firewall-cmd --list-all
sudo ss -tulpn

Only forward the ports that are necessary. Australian ISPs may block or filter selected inbound ports, and CGNAT can prevent forwarding altogether. For home administration, a WireGuard VPN is usually safer than exposing SSH or a web administration panel directly.

Keep records of the hostname and IP addresses carefully. Under the Australian Privacy Act 1988, an IP address can form part of personal information when it is connected with an identifiable person. Avoid publishing home-lab details unnecessarily; contact the publication if a documentation issue needs clarification.

Secure The Host And Keep It Reliable

Dynamic DNS is only the naming layer. Use Fedora updates, strong authentication, and a restrictive firewall policy, and consider disabling password-based SSH in favour of keys. If the hostname points to a residential connection, avoid exposing dashboards, cameras, or development applications without authentication and encryption.

Before relying on the service, verify these operational details:

Australian households often leave the NBN router running continuously, but a power outage, modem replacement, or ISP migration can change the WAN address and network topology. Check the update after such events, and review whether the provider has moved the service to CGNAT or changed its IPv6 delegation.

The key point is that ddclient keeps a DNS name aligned with a changing address; it does not provide reachability, encryption, or access control. Confirm the public addressing model first, secure the Fedora host, and remember that a successful DNS update is only the beginning of a safe remote-access setup.