Just finished working through a problem with one of my XG sites.
The site has an XG210 running SFOS 17.5.4 MR-4-1. Under Network > DNS, I have two IPv4 DNS servers configured, both internal to the LAN (.232 and .233, for reference). There is no IPv6 connectivity either in-site or out-of-site. There's a split-horizon DNS in place so that services hosted on premise resolve locally on the LAN, or to the XG on the Internet.
Clients are configured by DHCP to use the XG as primary DNS, and .232 and .233 as secondary/tertiary. I've done this so we get a bit more "intelligence" in Sophos ATP.
Today we restarted the two internal DNS servers for maintenance (patching etc). After doing so, the Sophos was returning the Internet DNS entries for internal services.
Where do I stop the XG from "helping"? This is not the behaviour we need - we had 50 clients reporting certificate errors, failing to connect to services and generally screwing up. I am aware that systemd has been "enhanced" (/s) to fallback to Google - but I wasn't aware this was still enabled on XG, if that's possibly the cause?
This thread was automatically locked due to age.