Docs
IP Change Runbook
When the Home IP Changes
The recovery sequence for Nextcloud and the WordPress sites whenever the ISP-issued public IP changes — written for tomorrow’s router replacement, but good for any future IP change too.
Covers: ahaddad.duckdns.org & ahaddad-wp.duckdns.orgServer: 192.168.100.13Last verified: 2026-08-21
When the Home IP Changes
The recovery seqordPress sites whenever theISP-issued public IP changes — written for the router replacement, but good for any future IP change too.
Before the technician leaves
Ask them to keep the LAN on 192.168.100.0/24, gateway 192.168.100.1.<
Every static address in the house — the server, the switch’s own admin
IP — assumes exactly this ranto
Plug the new router i>port 9 or 10 — never1–8.
Ports 1&ndasware-limited to 100Mb, permanently,no setting fixes it. Landing the router there silently caps your whole connection again, exactly like before.
Recovery sequence, in order
1
Confirm the server still has a network
Checks the pfails, nothing below it can work— and the fix is the LAN/router setup, not DNS or Docker.
R
ip -br addr show usb-eth-hub
ping -c 3 192.168.100.1
ping -c 3 8.8.8.8 # the internet
✓ucceed. If the router ping fails,the LAN subnet likely doesn’t match — revisit ask 1.
2
Re-create port forwardi
The old router’s forwarding rules live inside that specific device. A
full replacement means a blank routash; DNS can be perfect and theserver perfectly healthy, and the outside world still can’t get in without this.
Aouter’s admin page
External 80/tcp → 192.168.100.13:80
External 443/tcp → 192.168.1
3
Let the DNS auto-update happen — or trigger it yourself
Both domains public IP before anyone, includingyou, can reach the sites by name. A cron job runs duck.sh every 5 minutes
and self-corrects.
Just wait up to 5 minutes. To check or force it sooner
curl # today'sactual public IP
getent hosts ahaddad.duckdns.org S currently says
~/duckdns/duck.sh # force an update right
now
✓ Expect: the two values match. If they still don't after
5+ minutes, see the reference table
4
Verify the sites are actually reachable
Each test be; DNS, port-forward, or the appitself — so a failure tells you exactly where to look.
Lely
curl -sk -o /dev/null -w "HTTP %{http_code}\n" \
--resolve ahaddad.duckdns.org:443
https://ahaddad.duckdns.org/
✓"mono">HTTP 302
External test
Open and https://ahaddad-wp.duckdns.org/ in a browser, ideally on a phone off Wi-Fi (real
outside path).
If anything looks wrong, check container health
dockames}}\t{{.Status}}"
✓ Expect: every row reads Up /
(healthy)
5
Nextcloud's trusted-domains list — no action needed
Nextcloud one it's accessed by, ahaddad.duckdns.org, never the IP behind it. That hostname doesn't change, only
what it resolves to. This step is hi> to go looking for something tofix inside Nextcloud.
If something's still broken
Symptom Layer Check
Can't ping 192.168.100.1 at all
LAN / router config
New router likely defaulted to a different subnet — revisit ask 1
Local test passes,
Port forwarding
Re-check the two NAep 2)
DNS still shows the old IP after 5+ min
DNS / cron
~/duckdns/duck.sh, then crontab
-l and catd>
Resolves and connects, but shows 502
Docker containers
docker ps -a — restart whichever isn't healthy
Everything works bu>
Switch port
Confirm router and t 9 or 10, not 1–8
Confirm the server still has a network
Checks the pfails, nothing below it can work— and the fix is the LAN/router setup, not DNS or Docker.
ip -br addr show usb-eth-hub
ping -c 3 192.168.100.1
ping -c 3 8.8.8.8 # the internet
Re-create port forwardi
The old router’s forwarding rules live inside that specific device. A full replacement means a blank routash; DNS can be perfect and theserver perfectly healthy, and the outside world still can’t get in without this.
External 80/tcp → 192.168.100.13:80
External 443/tcp → 192.168.1
Let the DNS auto-update happen — or trigger it yourself
Both domains public IP before anyone, includingyou, can reach the sites by name. A cron job runs duck.sh every 5 minutes and self-corrects.
curl # today'sactual public IP
getent hosts ahaddad.duckdns.org S currently says
~/duckdns/duck.sh # force an update right
now
Verify the sites are actually reachable
Each test be; DNS, port-forward, or the appitself — so a failure tells you exactly where to look.
curl -sk -o /dev/null -w "HTTP %{http_code}\n" \
--resolve ahaddad.duckdns.org:443
https://ahaddad.duckdns.org/
Open
dockames}}\t{{.Status}}"
Nextcloud's trusted-domains list — no action needed
Nextcloud one it's accessed by,
If something's still broken
| Symptom | Layer | Check |
|---|---|---|
| Can't ping 192.168.100.1 at all | LAN / router config | New router likely defaulted to a different subnet — revisit ask 1 |
| Local test passes, | Port forwarding | Re-check the two NAep 2) |
| DNS still shows the old IP after 5+ min | DNS / cron | ~/duckdns/duck.sh, then crontab -l and catd> |
| Resolves and connects, but shows 502 | Docker containers | docker ps -a — restart whichever isn't healthy |
| Everything works bu> | Switch port | Confirm router and t 9 or 10, not 1–8 |