Custom DNS Entries Not Resolving

Comments

12 comments

  • Avatar
    Support Team

    Can you help share the screenshots of the custom dns configs that didn't work as expected?

     

     

    0
    Comment actions Permalink
  • Avatar
    charliebone

    Sure thing. A screenshot of the rules is included below. Things to note:

    1) These are all subdomains of the same mydomain.com FQDN which I own.

    2) Certain subdomains, such as plex.mydomain.com, are also defined at Cloudflare and point towards the WAN IP of my firewalla, so that I am able to access them externally.

    3) Some subdomains, such as omada.mydomain.com I would like only defined on the internal dns. 

    4) While tinkering, I opted to enable the beta yesterday evening and upon the firewalla reloading with the beta software, all of the domains resolved as expected. However after some time they reverted back to not working / resolving to the global DNS entry depending on the domain. While they were working as expected, I noticed the nameserver returned by the DNS was called "firewalla.int.mydomain.com" and the IP was the gateway / firewalla for the hosts I checked. However once they stopped the IP of the responding nameserver was the same however the name became "UnKnown." After enabling the beta and noticing these domains were working, I made no other configuration changes. The only thing that caused them to stop working seemed to be time.

    So in short, the dns configs seem to fall back to ignoring these custom dns entries after some time after they work initially. 

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    I created a ticket for you. The team may need to know a bit more info on the partthat was censored. 

    0
    Comment actions Permalink
  • Avatar
    Neal

    I have this same issue.  No local/custom DNS rules work for me using Firewalla.  So I'm very interested in this issue as well as any fix.  Thank you.

    1
    Comment actions Permalink
  • Avatar
    charliebone

    In my case, the issue was that the device(s) I was testing the custom dns entries on had emergency access enabled as I was testing different firewalla setups. I believe that when emergency access is turned on or monitoring is disabled for a particular device, traffic from that device completely bypasses the internal firewalla dns server. This means everything in the blue box in the flowchart at https://help.firewalla.com/hc/en-us/articles/4570608120979-Firewalla-DNS-Services#h_01FYDNB0ES9W93ZANPZ6YTE1M9 will be bypassed.

    Once I disabled emergency access, the custom dns entries worked as expected on my devices.

    0
    Comment actions Permalink
  • Avatar
    Bart Strauss

    I'm experiencing similar.

    I have two public addresses configured to point to my FWGold. 

    www.SiteA.com
    www.SiteB.com

    They're accessible externally just fine.  Web server is giving content.

    If I try to reach those sites from the internal network, I can't reach them.  If I nslookup either address, it resolves my external IP.
    If I add Custom DNS to the internal IP of the web server, nothing changes.  Still external IP.

    This is actually two issues that need to be solved:

    • Why isn't Custom DNS not working?
    • Why isn't hairpin routing not working?
    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Did you turn off DNS booster? using any external DNS?

    0
    Comment actions Permalink
  • Avatar
    Bart Strauss

    Turning off DNS Booster had no effect.

    DNS is managed by the Firewalla.  No secondary DNS is configured for clients.

    0
    Comment actions Permalink
  • Avatar
    1980cyber

    How about private browsing or browsers using their own DNS servers?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    hairpin should work, can you check if your web browser blocks connection from private IP (from inside your LAN)? 

    0
    Comment actions Permalink
  • Avatar
    Bart Strauss

    As for Private Browsing / Browsers with own DNS.  Not sure that this is a solution.  In any case, this is an issue on multiple devices (with different OSes/Browsers) on the LAN.

    If I browse to http://internal.IP.of.Server from any LAN device, I land on the default page configured in my IIS with no issues.  Of course, binding doesn't work this way.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Best to have you describe a bit of your network and how your applications are forwarded from outside to inside. I have created a ticket for you, and you can write any response via that ticket. 

    0
    Comment actions Permalink

Please sign in to leave a comment.