Bridge DNS forwarding problem
VPN300 V5.37(ABFC.2)
USG FLEX 200 V5.41(ABUI.0)
So I think sadly nothing can be likely done for the VPN300 thats EOL but I might be able to workaround that but the problem happens on FLEX 200 so I be thankful if this could be fixed.
The issue I'm seeing is I have a bind server with WAN IP does lookup from root servers you can see here the from DNS server a DNS query is sent in this case sig.cloud.zyxel.com with transaction ID 0x8082 no reply
Then a view from DMZ side of the Bridge
Then a view from WAN side of the Bridge which you can see a reply but FLEX200 didn't pass it on over the DMZ
All Replies
-
Hi @PeterUK
Could you share the topology and packet flow of this scenario? And we also need the remote access to VPN300 and FLEX200 to check this issue.
Zyxel Melen0 -
Ok Melen you can have remote access to VPN300 and FLEX200 to check this issue I was hoping you could of done internal testing given its DNS and how important it is. My guess is the FQDN system might be causing this problem?
simple topology
internet > VPN300 > FLEX200 > DNS server
0 -
update on problem for anyone following
Now with a simple setup DNS server on VLAN55 to SNAT SFP WAN the cause looks to be if you have any WILDCARD FQDN in use this cause some DNS replies to not be forwarded from WAN to LAN and can happen to any query for LAN to WAN that a reply may not make it from WAN to LAN.
0 -
Update on which might be the issue?
Bind adds this additional records which USG should ignore when Snooping DNS replies but maybe at times its not doing this correctly?
0 -
It seems the update to V5.42 has made this issue worse😕
0 -
Siprep …its really…really bad like from somewhat useable to somewhat unusable.
like I my bind can't DNS
e11290.dspg.akamaiedge.net
It sand the DNS out the reply comes back but the FLEX200 will not forward the answer.
I've had to do a hack which the XS1930-10 can do but limited vs what another switch can do so that the DNS server is a bridge by FLEX200 WAN side and DMZ side then have the XS1930-10 use the "Send the packet to the mirror port" for UDP source port 53 to go around the the FLEX200 in a bypass.
This now needs fixing please.
0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 219 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.5K Security
- 588 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 298 Service & License
- 477 News and Release
- 91 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 105 Security Highlight
Guru Member



Zyxel Employee
