Why does DNS resolution fail when using a VTI interface through a site-to-site VPN?

Options
Zyxel_Stanley
Zyxel_Stanley Posts: 1,435 image  Zyxel Employee
100 Answers 1000 Comments Friend Collector Eighth Anniversary
edited December 3 in VPN

Question:
Why couldn’t my DNS server resolve domain names when using a VTI interface through a site-to-site VPN, and why did it only start working after specifying the DNS server’s IP address directly?

Answer:
DNS resolution failed because the VTI (Virtual Tunnel Interface) was not fully configured to allow proper traffic forwarding between the VPN firewalls. For VTI to function correctly, both VTI interfaces should be assigned IP addresses within the same subnet to ensure seamless routing.

When the DNS server’s IP address was entered directly, the firewall was able to send queries to the correct destination.(local-out traffic)

image.png