Edge Firewall

FortiGate DDNS with DynIP

FortiOS includes a built-in dynamic DNS client under config system ddns, but only a handful of vendors are listed in the dropdown — and most of those have either shut down or are now hostile to non-enterprise customers. The escape hatch is genericDDNS, which speaks native RFC 2136 over UDP/53 with TSIG authentication. DynIP runs an authoritative nameserver that accepts those updates directly, so you can drop the FortiNet DDNS subscription and stop fighting third-party DDNS agents. No update scripts on the firewall, no external automation host — the FortiGate writes its DNS record itself.

Before you start: set the zone's algorithm to HMAC-MD5

FortiGate genericDDNS is fixed to HMAC-MD5 and exposes no algorithm toggle. New DynIP zones default to HMAC-SHA256, so before configuring a FortiGate, open the zone's Options modal in the dashboard and switch the algorithm to HMAC-MD5. The TSIG secret stays the same when you switch — only the algorithm changes. If you skip this step the FortiGate's signed updates will fail TSIG verification. See the TSIG algorithms reference for details.

Why this is the right call for FortiGate

For a single-site appliance it's a convenience: one less moving part. For multi-site or SD-WAN deployments it's significant infrastructure. Every branch FortiGate gets its own DDNS-tracked hostname, every hostname is provisioned in seconds from the DynIP dashboard or API, and the same TSIG-authenticated update mechanism works whether the WAN comes back on the same IP, a different IP, a different ISP, or an LTE backup. There's no per-tunnel reconfiguration when an IP changes — the hostname is what the IPsec or SD-WAN policy points at, and the hostname always resolves correctly.

What you'll need

  • A FortiGate running FortiOS 6.0 or newer (the genericDDNS provider has been around since 5.x but the syntax stabilized in 6.0).
  • A DynIP zone, e.g. branch01.ddns.dynip.dev. For multiple sites, register one zone per device — the free tier covers up to five, paid tiers go higher.
  • The TSIG key from the DynIP dashboard, with the zone's algorithm set to HMAC-MD5 (see the note above). FortiOS genericDDNS doesn't expose an algorithm toggle and only speaks HMAC-MD5, so the zone must be switched to MD5 in the Options modal before the FortiGate's updates will verify.
  • The DynIP update server, shown in the snippets-generator as update.dynip.dev.
  • Outbound UDP/53 reachable from the FortiGate (any sane policy already allows this; mention it here only because some hardened environments block egress DNS to anything but a corporate resolver).

Setup

1. Get the snippet from the dashboard

In the DynIP dashboard, open the zone, click "Snippets", and pick FortiGate. The output is a ready-to-paste CLI block already filled in with your zone name, key name, and key secret. Copy it into a scratchpad — you'll paste it into the FortiGate CLI in the next step.

2. Apply the config on the FortiGate

SSH into the FortiGate (or open the CLI console from the web UI) and paste the snippet. The structure is:

config system ddns
    edit 0
        set monitor-interface "wan1"
        set ddns-server genericDDNS
        set ddns-server-addr "update.dynip.dev"
        set ddns-domain "branch01.ddns.dynip.dev"
        set ddns-zone "branch01.ddns.dynip.dev"
        set ddns-auth tsig
        set ddns-keyname "key-branch01.ddns.dynip.dev"
        set ddns-key "YOUR_TSIG_SECRET"
    next
end

Change monitor-interface to whatever your WAN interface is named (wan1, wan, port1 — depends on the model). FortiGate triggers an update whenever it detects an IP change on that interface, plus a periodic refresh at the default interval.

3. (Optional) Pin the source interface for the DNS UPDATE

On multi-WAN units, FortiOS picks an egress for the DNS UPDATE based on the routing table. If you want the update to always exit a specific WAN (so DynIP records the IP of that WAN even when SD-WAN steers traffic over another), add an explicit policy route for UDP/53 to update.dynip.dev's addresses.

4. SD-WAN and multi-site rollout

For a fleet, generate one zone per FortiGate in the DynIP dashboard or via the REST API. Each zone gets its own TSIG key — do not share a key across devices. Push the snippet to each FortiGate via FortiManager scripts, Ansible's fortios_system_ddns module, or a Terraform run. The genericDDNS config block is idempotent, so re-applying on a device that's already configured is a no-op.

Verification

On the FortiGate:

FGT # diagnose debug application ddnscd -1
FGT # diagnose debug enable
# Trigger an update by toggling the WAN interface, or wait for the periodic refresh.
# Expected output includes: "ddns_send_update success" with the current IP.

FGT # diagnose debug disable

From an external host:

$ dig +short branch01.ddns.dynip.dev
203.0.113.42

Common issues

Update fails with "BADKEY" or "NOTAUTH" in the ddnscd debug

The TSIG key name or secret doesn't match. The key name must be the full key-<zone> string from the dashboard — missing the key- prefix is the most common cause. Re-copy from the snippets-generator to be sure.

"ddns-key" rejected at the CLI

FortiOS treats the key as a password field. If your secret contains characters the shell parser dislikes, quote it with double quotes (which the snippets-generator already does). If pasting via SSH strips the quotes, paste through the web UI's CLI console instead — it handles quoting reliably.

Updates silently never happen

FortiOS only sends an update when it detects an IP change on the monitored interface. On a static IP it'll never fire, which looks broken but isn't. To force a refresh, toggle the interface or rerun the edit 0 ... next end block to re-trigger the registration. For genuinely dynamic WAN, ensure the monitored interface is the one that actually changes.

Wrong IP recorded after WAN failover

FortiOS sends the update from whichever interface holds the route to update.dynip.dev, which after failover might not be the WAN you intended. If you want the update to always reflect a specific WAN's IP, add a policy route forcing UDP/53 to DynIP's update endpoint out that interface.

Related guides

  • UniFi UDM / UDM Pro — one-line SSH installer with a self-contained polling updater and reboot persistence.
  • Caddy + DynIP — if you're terminating TLS behind the FortiGate, Caddy issues Let's Encrypt certs via the same DynIP zone.
  • TSIG algorithms reference — the HMAC-SHA256 default, why FortiOS needs HMAC-MD5, and how to switch a zone's algorithm.