Replace ISP DNS by custom ones

mat17
mat17 Posts: 45  Freshman Member
First Anniversary 10 Comments Friend Collector

Hello,

sorry if this is not the appropriate category for this subject.

Recently, my ISP had issues with his DNS. So I tried some custom ones (other than the Google ones).

Their performance is limited: DNS resolution take seconds.

So I would like to cache these DNS queries in the FW: It means replace the ISP DNS by these custom ones, and use the ZyWALL as the only DNS server.

First, can you confirm that the ZyWALL caches the DNS queries?

Also, I've seen we can add custom DNS in the ZyWALL, but we cannot remove the ISP ones. My knowledge is limited on this point: Why we cannot remove the ISP ones?

If I add my 2 custom ones with priority 1 and 2 (the ISP ones can't be edited, so they have priority *), can you explain to me how the DNS resolution is made? My custom ones would answer, but probably less fast than my ISP ones (when they are available…). Does the time to answer is taken into account? Or does the ZyWALL proceed the first one, and if it did not get any answer proceed the #2, etc?

Thanks in advance for your help

Kind regards

Accepted Solution

  • PeterUK
    PeterUK Posts: 2,704  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited March 2023 Answer ✓

    Yes I don't like the fact you can't remove ISP DNS or have the zywall do its own recursion.

    See here and vote

    https://community.zyxel.com/en/discussion/10818/remove-auto-added-dns-as-forwarder

    Having a DNS 1st and 2nd in the list with * should use them DNS as forwards first then go to the next

All Replies

  • PeterUK
    PeterUK Posts: 2,704  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited March 2023 Answer ✓

    Yes I don't like the fact you can't remove ISP DNS or have the zywall do its own recursion.

    See here and vote

    https://community.zyxel.com/en/discussion/10818/remove-auto-added-dns-as-forwarder

    Having a DNS 1st and 2nd in the list with * should use them DNS as forwards first then go to the next

  • mat17
    mat17 Posts: 45  Freshman Member
    First Anniversary 10 Comments Friend Collector

    Thank you Peter.

  • PeterUK
    PeterUK Posts: 2,704  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited March 2023

    One problem with Zywall that I posted about is that a working DNS where Zywall will randomly not accept the reply and sends out ICMP Destination unreachable and jumps to the next DNS forwarder.

Security Highlight