Why does DNS resolution fail when using a VTI interface through a site-to-site VPN?
Options
Zyxel_Stanley
Posts: 1,481
Zyxel Employee
Zyxel Employee
Question:
Why couldn’t my DNS server resolve domain names when using a VTI interface through a site-to-site VPN, and why did it only start working after specifying the DNS server’s IP address directly?
Answer:
DNS resolution failed because the VTI (Virtual Tunnel Interface) was not fully configured to allow proper traffic forwarding between the VPN firewalls. For VTI to function correctly, both VTI interfaces should be assigned IP addresses within the same subnet to ensure seamless routing.
When the DNS server’s IP address was entered directly, the firewall was able to send queries to the correct destination.(local-out traffic)
0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 691 USG FLEX H Series
- 365 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 312 Service & License
- 508 News and Release
- 97 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.1K FAQ
- 34 Documents
- 89 About Community
- 114 Security Highlight
