Domain Zone Forwarder redundancy

IT_Field_Support
IT_Field_Support Posts: 96  Ally Member
edited April 2021 in Security
Hi all,

We have noticed some anormal behaviour on our many USG40w and Domaine Zone Forwarder.
We are using 4 DNS server for private zone.
After making some tests, we realise that if the first server on the list was not available for the zone xxx, the DNS request timeout without result.
The router does not failover on the other Domaine Zone Forwarder  as we thought.

Could you tell us if it is a normal behaviour and how should act the Domain Zone Forwarder ? I cannot find any technical documentation on that.

Thanks,

Davy


All Replies

  • Zyxel_Emily
    Zyxel_Emily Posts: 885  Zyxel Employee

    Hi @IT_Field_Support,

    If USG cannot query the first DNS server, it will then uses the second DNS server to query.

    In this example, create a fake DNS server 5.4.3.2 as the first DNS server and 8.8.8.8 as the second DNS server.


    Connect one laptop in lan1 and open some websites.

    Capture DNS packets in lan1.


    In the packet trace, the first DNS server 5.4.3.2 doesn’t reply. Only the second DNS server 8.8.8.8 replies.

    It means USG uses the second DNS server to query.


Security Highlight