Failing DNS calls aren't showing up in the Flows

Comments

3 comments

  • Avatar
    Firewalla

    DNS queries are NOT real flows, and they probably can be blocked anywhere. coralogix.com is associated with logging, so it is likely it is an ad or tracker. if you tap on the network flows, and tap on top right "view blocked", see if you can see it. (Sometimes you can)

    Edit: my coworker told me you can tap on rules, tap on the top right (...) and tap on Diagnostics, you should be able to enter the domain and it should tell you why it is blocked. 

    Can you turn off ad blocker and see if it will fix the issue? You can also add an "allow rule to coralogix.com" to the box having issues, it should also fix the issue.

     

    0
    Comment actions Permalink
  • Avatar
    Caleb Call

    Thanks, I did look at the blocked flows and these calls didn’t show up there. Coralogix.com is just an example. (I was trying to review them as a vendor and couldn’t visit their site). I’m seeing the same behavior on lots of DNS requests, as mentioned even trying to issue ssl certs on domains I own and have only ever been used for my own private use. I could add allow rules if I knew what was being blocked, for the cert issuance, I don’t know if it’s trying to query the domain I own, the cloudflare api where my domain is hosted, etc (hence why I’m trying to find the blocked calls). I’ll try the diagnostics idea and see what it can provide.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    If you see many blocks, the best way is to clean up the rules, such as removing ad blockers, target lists ... and then slowly add them back. If you know exactly what you are accessing, then allow rules should be used.

    0
    Comment actions Permalink

Please sign in to leave a comment.