Client cannot access website through FLEX H sereis

Zyxel_Kevin
Zyxel_Kevin Posts: 948  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 500 Comments

Question:

Client cannot access website through FLEX H sereis, It said DNS can't resovled, but the domain can be resolved through nslookup/dig

Root cause:

This is beacuse you used DNS over HTTPS, You would find queiry type65 in packets capture, such like

ethertype IPv4 (0x0800), length 70: 192.168.121.33.47647 > 8.8.8.8.53: 3321+ Type65? dns.google. (28)

If DNS is not transmitted in plain text, our security will not be able to check it.

Workaround:

1)Please disable DoH on your browser.

2)or change the action of "DNS over HTTPs/TLS detection to "Pass"

image.png