Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DNS Lookup Issue

DNS lookup started failing today but only for one website.

Results return as 0.0.0.0 and page loads in browser report DNS_PROBE_FINISHED_NXDOMAIN

Compare the results of a DNS lookup against router vs. against the external DNS server directly:

ipconfig/flushdns

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

nslookup
Default Server: UnKnown
Address: 192.168.xxx.1

> www.dailywire.com
Server: UnKnown
Address: 192.168.xxx.1

Non-authoritative answer:
Name: cname.vercel-dns.com
Addresses: ::
0.0.0.0
Aliases: www.dailywire.com

nslookup - 1.0.0.3
Default Server: UnKnown
Address: 1.0.0.3

> www.dailywire.com
Server: UnKnown
Address: 1.0.0.3

Non-authoritative answer:
Name: cname.vercel-dns.com
Address: 76.76.21.21
Aliases: www.dailywire.com

And here are the results of a DNS lookup inside the firewall interface:

DNS Lookup issue

I conducted further troubleshooting with security and firewall rules but saw no other relevant data to report. The website works fine from my cell phone when NOT connected to Wi-Fi.

The important error seems to be the failure to return the correct address instead returning 0.0.0.0.  Other names will resolve to IPv4 addresses or combination of IPv6 and IPv4 addresses and one can reach the website. This address resolved just fine until sometime late yesterday.



This thread was automatically locked due to age.
  • I found that adding another DNS provider to the firewall (in my case I added 9.9.9.9) fixed the problem.

    There must be some communication problems currently occurring between the Sophos XG making the DNS request and the reply from One and One DNS.