soapyfish Posted November 25, 2024 Posted November 25, 2024 Hi All, HELP, I am struggling with DNS. What Works When I make a DNS request from the subnet 172.19.152.0/21 or any of our other subnets (used for BYOD etc), our existing Domain controllers service this request and either answer directly or pass the query to ISP DNS server which are configured as forwarders, This works fine. What Does not Work If I try and make a DNS request directly to the ISP provided DNS servers from some subnets it works but from others it does not. We have a Smoothwall inline between the ISP router and out core switch which is the gateway for all VLANS/Subnets. 1) The ACL rules on the Core switch are allowing traffic 2) The Smoothwall is not logging anything in the firewall logs that refers to the ISP provided DNS servers 3) When I try to use "nslookup bbc.co.uk smoothwalls ip address" I get the following ***UnKnown Can't find bbc.co.uk: Query refused Does anyone have any idea I am tearing my hair out!
simpsonj Posted November 25, 2024 Posted November 25, 2024 On the Smoothwall, what's set in Network - Configuration - DNS?
soapyfish Posted November 25, 2024 Author Posted November 25, 2024 User defined is selected Primary and secondary DNS is set to my existing 2 domain controllers.
simpsonj Posted November 25, 2024 Posted November 25, 2024 Just for reference, mine is set to: System internal DNS Server DNS Forwarder - Google DNS ( 8.8.8.8) Conditional Forwarders (my 2 domain controllers) Static DNS hosts (my 2 domain controllers) Domain controllers forward onto the Smoothwall I don't know if this is best practice, but it's working here!
soapyfish Posted November 25, 2024 Author Posted November 25, 2024 Thanks but I don't think those changes will help us, I suspect that a firewall rule is the cause but I am not able to locate it in the GUI and the firewall logs also don't seem to show anything that I have been able to locate.
simpsonj Posted November 25, 2024 Posted November 25, 2024 Maybe try creating a top level Firewall Rule - Any Source IP - Any Inbound Interface - Any Destination - Any Outbound Interface - DNS Service - No Applications - Any Group - Action - Allow - Tick Log and see if that picks up anything?
Olliedawg Posted November 25, 2024 Posted November 25, 2024 Maybe try creating a top level Firewall Rule - Any Source IP - Any Inbound Interface - Any Destination - Any Outbound Interface - DNS Service - No Applications - Any Group - Action - Allow - Tick Log and see if that picks up anything? Was just going to suggest that. How are you allowing DNS out currently?
Joeloman Posted November 26, 2024 Posted November 26, 2024 I really recommend that you use "System internal DNS server" as DNS quite often gets overloaded with long response times and timeouts. Try the response time of different "DNS forwarders" at different times when you have students in place. Sometimes the provider's DNS can be overloaded. So also try with at least Google 8.8.8.8 and 8.8.4.4 + Cloudflare 1.1.1.1 Then you need to make sure that you specify the reverse lookup zone for your conditional DNS forwarders and that you make sure that the DNS Proxy (53) is open for service for all subnets under "Smoothwall access" See this KB for more info:https://kb.smoothwall.com/hc/en-us/articles/15301651296156-Add-new-DNS-forwarders-or-hosts 1
Davit2005 Posted November 26, 2024 Posted November 26, 2024 (edited) Personally I'd say to only allow DNS servers to talk to external DNS servers and that is it. Your general user is not going to know what DNS does and will leave it to DHCP. Edited November 26, 2024 by Davit2005
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now