Domain Zone Forwarders not working
All Replies
-
This is the result I get from the nslookup diagnostic within the firewall so you can see it isn't forwarding the request to the zone forwarder but rather the global forwarder
If I open up advanced settings and specify the remote DNS server it just times out, like the firewall is ignoring its own static routes. However, if I put the 155.231.231.1 DNS server into a windows laptop behind the firewall I can resolve and reach destinations fine, so the static route is working.
0 -
Did more testing, setup a Windows DNS server, put the forwarders in and pointed a machine on the LAN at it and DNS resolved perfectly so it is 100% the firewall zone forwarders that are not working.
0 -
In my testing the way I got it to work is your end for local IP/subnet in VTI setting needs to match your LAN is my case is 192.168.255.42/255.255.255.240 and 192.168.255.42 must not be in use.
On the remote site in your case NHS their local VTI must match your local IP/subnet in my case 192.168.255.43/255.255.255.240 and 192.168.255.43 must not be in use.
Then when your client at say 192.168.255.40 uses DNS 192.168.255.39 to Zywall it will use the Domain Zone Forwarders for NHS goes via VTI to IP NHS or in may case 192.168.55.2
0 -
Thanks for this Peter, we seem to be getting somewhere.
So my local firewall is on 192.168.170.254/255.255.255.0, I've changed the VTI address in the IPSEC VPN settings to be 192.168.170.253/255.255.255.255.
This has got the firewall to start resolving the address when testing using NSLOOKUP.
And my device on 192.168.170.1 using the firewall on 254 as its DNS resolver can resolve addresses on the nhs.uk domain.
But performance is really poor. I am getting dropped packets to the VTI interface.
The remote end of the VPN is setup by a third-party supplier so I have no visibility of their VTI settings, and to be honest, they have never mentioned them so I am not even sure if they are in use.
0 -
Right well this is very weird, I changed the VTI again to a different IP, that broke it all, I put it back to 192.168.170.253/255.255.255.25 and now everything is working perfectly!
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight