DNS Resolution
Hi guys,
I have an issue with one of our USG40W. Name resolution is not working from laptop on the network but it is working from the router itself. It seems that the router doesn't forward dns request to the dns server in the zone-forwarder.
The first DNS of the laptop is the router itself so if the router doesn't resolve, it should forward the request to one of the 4 servers we have in the zone-forwarder.
Cannot find a way to debug this..
Thanks,
Davy
All Replies
-
Security policy should allow port 53 to zywall0
-
HI IT_Field_Support if the problem conditions & symptoms are something like these:
- LAN client local host name resolution local locks up and times out or
- LAN client public host name resolution locks up or times out
- host in VTIx site-to-site suddenly stops resolving via Forward DNs
- or the local USG router nslookup hostname - times out
- and you might be at Firmware V4.32 to V4.35 and/or
- on USG20WVPN and or USG40 or USG60
- AND the above Zyxel appliances are very low CPU busy (< 5%) and
- the above Zyxel appliances are unusable via the HTTPS UI and extremely slow via ssh CLI
- and telnet you-USG40W-ipv4-address 53 times out despite the fact you can ping -c 3 telnet you-USG40W-ipv4-address and it in a few ms ....
- and the USG40W briefly responses like normal after 3 minute restart/boot then 1.-8. above occurs within 2 mins again THEN
its probable that you might consider resetting the USG appliance and restore the startup.conf. or clone ... This fixes it immediately!
We had this issue of since V4.32 firmware.
Steps to resolve possible symptoms 1-9 above :
- copy and rename your startup.conf via UI or ssh
- save it (goodUSG40W.conf) on a LAN host (Mac or PC etc)
- shutdown and RESEt the USG40W
- power it off and restart it (black button on rear)
- use default admin/1234 https;?? to the usg40w
- restore the above goodUSG40W.conf to the usg40w if its not there (it should be)
- restart from that config goodUSG40W.conf
You local name service lookup will work as long as you can telnet 53 top the USG (LAN1_SUBNET_client (your mac/pc) to router:port53 ...)
If you can't then enable DEBUG mode in the YSG40W logs for each section and have a look ..maybe the Security Policy is stopping you .. easily resolved.
We've performed this soon our own and some of our clients USG appliances and the routers comes good again... especially ones the have been in use for several years.
I'd be most curious if you have these issues above.
HTH
warwick
Hong Kong
0 -
Hi @warwickt
Thanks for your suggestion.
Before taking any actions. We would like to figure out what is the root cause of the symptoms since sometimes issue happens due to the environment issue per our experience.
Yes, if the router doesn't resolve, it will forward the request to list in the zone-forwarder.
Can you collect the packet on the device?
Go to Maintenance > Diagnostics > Packet Capture > Capture > select the port to detect DNS
After testing, go to Maintenance > Diagnostics > Packet Capture > Files > select the file and click Download
Don't miss this great chance to upgrade your Nebula org. for free!
0 -
Hi Zyxel_Jerry ICYM, refer to the following reply for the symptoms that we see when this occurs for DNS request failures...
at
https://businessforum.zyxel.com/discussion/3891/usg60-very-slow-web-interface#latest
regards
Warwick
Hong Kong
0
Categories
- All Categories
- 414 Beta Program
- 2.2K Nebula
- 131 Nebula Ideas
- 91 Nebula Status and Incidents
- 5.4K Security
- 178 USG FLEX H Series
- 258 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 36 Wireless Ideas
- 6.2K Consumer Product
- 236 Service & License
- 372 News and Release
- 79 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 81 About Community
- 69 Security Highlight