DNS: How to set up a private Domain Zone Forwarder

Ich
Ich Posts: 5  Freshman Member
First Comment

To resolve local DNS entries, I set up Domain Zone Forwarders (System|DNS) for the locally resolved domains.

Up to the classic USG Flex Series I was able to chose to set up "private servers". These where queried via "tunnel" which worked locally AND via VPN tunnel. The new USG Flex H series firewall forces me to chose the query via interface. Possible values are the physical and virtual network interfaces, but not the VPN tunnels.

Does anybody know how to set up DNS server hiding behind VPN tunnels?

Accepted Solution

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,744  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @Ich

    It is in our feature list, but we don't have a ETA currently.

    Zyxel Melen


All Replies

  • PeterUK
    PeterUK Posts: 4,020  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Does selecting auto help?

    If you do a VTI tunnel you can query via that interface

  • Ich
    Ich Posts: 5  Freshman Member
    First Comment
    edited August 27

    Auto is not available for "Domain Zone Forwarders"; only for "Global Zone Forwarders"…

    Until now I did never use VTI tunnels. Frankly, I don't understand, why they exist. I'll have to investigate into them a little bit more…

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,744  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Ich

    Since currently policy-based site-to-site VPN is not supported to select, we recommend to change your VPN setting from policy-based to route-based.

    You may feel free to provide your configuration and we will help to convert the VPN setting from policy-based VPN to route-based VPN. Please send me your configuration file to me via private message.

    Zyxel Melen


  • Ich
    Ich Posts: 5  Freshman Member
    First Comment

    You said "currently not supported"…

    Do you - or anyone else - know, if it is planned to restore the previous functionality?

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,744  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @Ich

    It is in our feature list, but we don't have a ETA currently.

    Zyxel Melen