Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAN Failover does not work on XG - DNS?

Hello...We have an XG firewall configured with (2) WAN interfaces.  The primary is a cable connection from COX. We have a second one configured as a Backup in the WAN link manager that is pointing to a CradlePoint router with a Cellular SIM installed.  That device has a dynamic IP.  This setup used to work fine on the SG we had installed but does not work on the XG so hopefully it is something we have configured incorrectly.  I am thinking the issue is DNS since the DNS on the XG is statically assigned to have the PRIMARY as the WAN IP of the COX pipe and the second and third point to 1.1.1.1 and 8.8.8.8.  We have read that we should have the secondary be the WAN IP of the secondary connection but it is dynamic so that is not possible.  The cellular is working fine since we can ping via the XG dianostics out that connection.  The failover rules are the default ones that come up when WAN link manager is configured.  All the client computers point to the XG LAN interface for DNS since we do not have an on prem AD server, etc.  

So perhaps the issue is the static DNS configuration?  Should I change it to automatic ?  I assumed it would use all (3) DNS servers in a failover scenario.

Thanks for any info.

Dave



This thread was automatically locked due to age.
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    DNS servers on XG are queried in the order specified.

    Could you please check the packet flow for DNS queries at the time of failover?

    ==> Login to SSH > 4. Device Console

    console> tcpdump 'port 53

    ==> In another SSH session check drop packets

    console> drop-packet-capture 'port 53

    I'd also suggest taking an observation once with global DNS 8.8.8.8 as DNS 1.