Domain zone forwarder through tunnel

Options
nielsscheldeman
nielsscheldeman Posts: 95 image  Ally Member
First Comment Friend Collector Third Anniversary

In FLEX (non H) series I was able to add a Domain Zone Forwarder in DNS to an IP-Address behind a tunnel. So the other site could resolve server.domain.local for example. I could select Private DNS Server then and then it mentioned "query via tunnel".

In FLEX H Series I don't have that option anymore, can only select one of the interfaces, but not tunnel. How can I resolve this? Do I have to work through routing rule?

«1

All Replies

  • PeterUK
    PeterUK Posts: 4,409 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    So I think the only way to resolve this is to setup VTI then you can select the VTI for DNS query via option.

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,531 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @nielsscheldeman

    Currently, only interface is selectable in here, includes VTI interface.

    image.png
    Zyxel Melen


  • nielsscheldeman
    nielsscheldeman Posts: 95 image  Ally Member
    First Comment Friend Collector Third Anniversary

    Hmm ok, is there a reason why this is now like this? Will have to test this out. Or will it in future firmwares be possible again to do it the old way?

  • PeterUK
    PeterUK Posts: 4,409 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    I would hope you be able to do it the way you did before but currently the FLEX H is still on going development.

  • nielsscheldeman
    nielsscheldeman Posts: 95 image  Ally Member
    First Comment Friend Collector Third Anniversary

    It's the 3rd issue I have with my upgrades/new installations to FLEX H series…(done 5 so far)

    In a way it doesn't feel like complete product, but I like it because of the full Nebula integration.

    My issues so far:

    • At first no EXT-GROUP-USER available to connect AD → solved now
    • No 2FA possible with EXT-GROUP-User → waiting for firmware update?
    • Domain zone forwarder through tunnel → workaround as mentioned above maybe, but if it's in the roadmap to be solved soon, I prefer to wait. However I will need it at another client in may/june.
  • Zyxel_Melen
    Zyxel_Melen Posts: 4,531 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @nielsscheldeman

    Sorry for the delayed reply; I was checking the information/solution to your questions.

    No 2FA possible with EXT-GROUP-User → waiting for firmware update?

    About this one, we won't implement this function for EXT-GROUP-User.

    For the not device local users, there has an alternate way for 2FA:

    💡Duo Security Authentication Integration Guide — Zyxel Community

    Domain zone forwarder through tunnel → workaround as mentioned above maybe, but if it's in the roadmap to be solved soon, I prefer to wait. However I will need it at another client in may/june.

    This feature is in our feature list, but schedule is TBD. So… you will need to set route-based VPN for your client in may/june.

    Zyxel Melen


  • OWB
    OWB Posts: 39 image  Freshman Member
    First Comment Friend Collector Sixth Anniversary

    Hi,

    I do have similar issue, and I'm not familar on how this "VTI" setup should be done. It's not my intension to "hijack" from thread starter, but can anyone guide me in the direction on how to do this "VTI" setup?

    Thank you.

    Best regards Ole

  • nielsscheldeman
    nielsscheldeman Posts: 95 image  Ally Member
    First Comment Friend Collector Third Anniversary
  • OWB
    OWB Posts: 39 image  Freshman Member
    First Comment Friend Collector Sixth Anniversary
    edited February 17

    Thank you for replying.


    myserver1 - mydomain.local - IP 1.1.1.1
    myserver2 - mydomain.local - IP1.1.1.2

    Like that for each server?

  • nielsscheldeman
    nielsscheldeman Posts: 95 image  Ally Member
    First Comment Friend Collector Third Anniversary

    Yes indeed, that will work :) If only couple of servers have to be reachable it will be much easier to implement this way then through VTI.

    You could also point DNS Server in your DHCP to Domain controller in other site, but all DNS traffic will pass through tunnel then.