DNS settings for dual WAN on USG FLEX 500


I would like to have DNS forwarders for dual WAN, that actually use the corresponding DNS for the WAN that is used. The DNS's used are fromthe providers and they don't allow request outside their network.

One of my WAN's is a static ethernet interface and I can't specify a DNS there. The other one is PPPoE and that one get's the DNS's automatically. In the DNS Domain Zone Forwarder, I can see the PPPoE DNS's. So that is ok. But I don't understand how to add the one for the static ethernet WAN there.

Maybe I am not getting the idea here. Can anybody help me?

Best regards,


Best Answers

  • PeterUK
    PeterUK Posts: 3,544  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited March 2023 Answer ✓

    The DNS are added to System > DNS >Domain Zone Forwarder you can use * to add another DNS to Query by interface here.

    They auto add the Query via given interface so they already use the corresponding DNS for the WAN if on your LAN DHCP set for DNS to use Zywall

  • PeterUK
    PeterUK Posts: 3,544  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited March 2023 Answer ✓

    Yes you can disable WAN1 interface to test only WAN2 that its working for LAN clients

    Due to limitations of the bind by zyxel all clients that have Zywall as DNS will use first but at times use default which is a bug.

    To make clients use a given DNS only set the DHCP DNS for the given DNS this will mean Zywall is not the cache.

All Replies

  • PeterUK
    PeterUK Posts: 3,544  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited March 2023 Answer ✓

    The DNS are added to System > DNS >Domain Zone Forwarder you can use * to add another DNS to Query by interface here.

    They auto add the Query via given interface so they already use the corresponding DNS for the WAN if on your LAN DHCP set for DNS to use Zywall

  • rvdweerd
    rvdweerd Posts: 3
    First Comment

    Thanks. So I now have two times * like in this screenshot:

    That should work?

    Best regards,


  • PeterUK
    PeterUK Posts: 3,544  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited March 2023 Answer ✓

    Yes you can disable WAN1 interface to test only WAN2 that its working for LAN clients

    Due to limitations of the bind by zyxel all clients that have Zywall as DNS will use first but at times use default which is a bug.

    To make clients use a given DNS only set the DHCP DNS for the given DNS this will mean Zywall is not the cache.

  • rvdweerd
    rvdweerd Posts: 3
    First Comment

    Ok thanks you for your help.

    Best regards,
