OK, so I'm running XG behind another device in a layered FW setup. So, basically WAN > (Edge Router) > DMZ > (XG) > LAN. In this configuration, I have my DMZ actually set as a WAN zone within the XG networking tab. I'm not sure if this matters, but it seems it might.
So anyway, I've got XG set as my DNS server and LAN clients have no problem with name resolution. Clients in the DMZ (remember, WAN zone from XG's perspective), when pointed at XG, can only resolve entries specifically set in the XG's DNS Host Entry mappings. Well, anything with "publish on WAN" checked. Everything else fails. It seems XG refuses to forward DNS requests to the upstream DNS server when those requests originate from the WAN zone.
Can someone comment on this? I suppose it makes sense to disable DNS forwarding for the WAN zone... but in a multi-layered FW approach, it would be nice to have the option to override this. Is that possible? Alternatively, I can always change this zone from WAN to DMZ, because that is what it really is. But then all of my DNS Host entries are available there... which I don't really want.
Any thoughts on this?
This thread was automatically locked due to age.