V5.42 DNS is broken with FQDN objects

Options
PeterUK
PeterUK Posts: 4,399 image  Guru Member
250 Answers 2500 Comments Friend Collector Eighth Anniversary
edited February 6 in Security

FLEX200 V5.42

If you have no FQDN objects you may likely not see a problem but if you do big problem as some DNS lookups will fail completely to pass through the USG no matter how many times you try.

Here it my bind and then DNS by 8.8.8.8

DNS.PNG

and this is a Wireshark view WAN side

Screenshot 2026-02-06 112734.png Screenshot 2026-02-06 112816.png

Accepted Solution

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,520 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @PeterUK

    It seems like the issue that Alex encountered. Let me provide you a date code firmware.

    Zyxel Melen


All Replies

  • alexey
    alexey Posts: 193 image  Master Member
    First Comment Friend Collector Eighth Anniversary

    Same situation.

    Yesterday i got ticket from our user, that don't work 1 site.

    DNS servers don't resolv it. Only it in this domain.

    [root@docker ~]# nslookup lsul.nalog.ru 46.61.250.141
    Server: 46.61.250.141
    Address: 46.61.250.141#53

    Non-authoritative answer:
    *** Can't find lsul.nalog.ru: No answer

    [root@docker ~]# nslookup lkul.nalog.ru 46.61.250.141
    ;; connection timed out; no servers could be reached

    [root@docker ~]# nslookup nalog.ru 46.61.250.141
    Server: 46.61.250.141
    Address: 46.61.250.141#53

    Non-authoritative answer:
    Name: nalog.ru
    Address: 37.220.164.100

    Zyxel, please, forgive your users! Make 1 stable FW for your devices.

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,520 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @PeterUK

    It seems like the issue that Alex encountered. Let me provide you a date code firmware.

    Zyxel Melen


  • Baraber
    Baraber Posts: 4 image  Freshman Member
    First Comment Second Anniversary

    The same problem is the resolution of some names on the internal DNS server by servers located in the DMZ Zywall USG Flex 200 V5.42(ABUI.0). Timeout...