Stuck on getting SSLVPN authentication with Microsoft Entra ID to work
All Replies
-
Hi @Zyxel_Melen
But this is an SSL VPN for remote access, how do I decide on route-based or policy-based? Or do I maybe misunderstand.
0 -
Hi @OWB
Please allow me to clarify first, is the DNS server connecting to the firewall by SSL VPN?
In my experience, the DNS server is normally connecting be LAN interface for local DNS server, WAN interface for public DNS Server, and site-to-site VPN for internal DNS server. That's why Domain forwarder query interface only support these types of interfaces.
Zyxel Melen0 -
Hi @Zyxel_Melen
No, the DNS server is not connected to the firewall by SSL VPN.
But it was my understanding from your previous post, that it must be handeled different, depending on if the SSL-VPN were route-based or policy-based, and I was not aware that it could be both?So, the Global
Zone Forwarder querying from WAN and pointing to our ISP DNS server, is the correct way for the firewall to reach login.microsoftonline.com?
Thank you.
Best regards Ole.0 -
Hi @OWB
We might mix different questions together. Please allow me to explain:
- "Route-based and policy-based are the two primary implementation methods of site-to-site VPN, which define how the VPN tunnel selects and handles traffic across IP subnets. These methods do not apply to remote access VPN (client-to-site)."
- The Global Zone Forwarder means the firewall will query all domain names to a specific DNS server. If some specific domains can only be resolved by a particular DNS server, or if the DNS server of the Global Zone Forwarder cannot resolve them, you can set a Domain Zone Forwarder rule to specify which DNS server should be used to query the DNS record.
Zyxel Melen0 -
Thank you, I got it. :-)
0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 220 Nebula Ideas
- 128 Nebula Status and Incidents
- 6.5K Security
- 606 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 299 Service & License
- 482 News and Release
- 92 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 105 Security Highlight
Freshman Member
Zyxel Employee
