Jump to content

Recommended Posts

Posted

Hi All,

 

HELP, I am struggling with DNS.

 

What Works

When I make a DNS request from the subnet 172.19.152.0/21 or any of our other subnets (used for BYOD etc), our existing Domain controllers service this request and either answer directly or pass the query to ISP DNS server which are configured as forwarders, This works fine.

 

What Does not Work

If I try and make a DNS request directly to the ISP provided DNS servers from some subnets it works but from others it does not.

 

We have a Smoothwall inline between the ISP router and out core switch which is the gateway for all VLANS/Subnets.

 

1) The ACL rules on the Core switch are allowing traffic

2) The Smoothwall is not logging anything in the firewall logs that refers to the ISP provided DNS servers

3) When I try to use "nslookup bbc.co.uk smoothwalls ip address" I get the following ***UnKnown Can't find bbc.co.uk: Query refused

 

Does anyone have any idea I am tearing my hair out!

Posted

Just for reference, mine is set to:

 

System internal DNS Server

 

DNS Forwarder - Google DNS ( 8.8.8.8)

 

Conditional Forwarders (my 2 domain controllers)

 

Static DNS hosts (my 2 domain controllers)

 

Domain controllers forward onto the Smoothwall

 

I don't know if this is best practice, but it's working here!

Posted
Thanks but I don't think those changes will help us, I suspect that a firewall rule is the cause but I am not able to locate it in the GUI and the firewall logs also don't seem to show anything that I have been able to locate.
Posted
Maybe try creating a top level Firewall Rule - Any Source IP - Any Inbound Interface - Any Destination - Any Outbound Interface - DNS Service - No Applications - Any Group - Action - Allow - Tick Log and see if that picks up anything?
Posted
Maybe try creating a top level Firewall Rule - Any Source IP - Any Inbound Interface - Any Destination - Any Outbound Interface - DNS Service - No Applications - Any Group - Action - Allow - Tick Log and see if that picks up anything?

 

Was just going to suggest that. How are you allowing DNS out currently?

Posted

I really recommend that you use "System internal DNS server" as DNS quite often gets overloaded with long response times and timeouts.

 

Try the response time of different "DNS forwarders" at different times when you have students in place.

 

Sometimes the provider's DNS can be overloaded. So also try with at least Google 8.8.8.8 and 8.8.4.4 + Cloudflare 1.1.1.1

 

Then you need to make sure that you specify the reverse lookup zone for your conditional DNS forwarders and that you make sure that the DNS Proxy (53) is open for service for all subnets under "Smoothwall access"

 

See this KB for more info:https://kb.smoothwall.com/hc/en-us/articles/15301651296156-Add-new-DNS-forwarders-or-hosts

  • Thanks 1
Posted (edited)

Personally I'd say to only allow DNS servers to talk to external DNS servers and that is it.

 

Your general user is not going to know what DNS does and will leave it to DHCP.

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...