I am curious if I can use my BIND9 server to provide dynamic dns for a couple IPsec tunnels I want to setup. 2 of the endpoints have dynamic IP addresses, the "main" endpoint is a static address.
I would use no-ip.org or something else but I want more control and don't want to pay for the pro version.
I already have DNSSEC running. So would I just expose the server to the internet via NAT? or should I do something to BIND9 to bolt it down? Maybe a separate domain?
As far as updates I would be using the Dynamic DNS server in my pfSense boxes they support for RFC 2136 (Dynamic DNS updates).
Any insight would be appreciated.