This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Routing Site-to-Site VPN Traffic on same Domain Computers

Currently, I have a Site-to-Site VPN, with split tunnels to specific IP's and networks, setup on both Sophos firewalls and they are working fine. BIGGEST THING TO REMEMBER, the branch office needs to have their computers on our internal Domain.

The branch office needs to see the DNS server, which it does, but cannot translate names of devices within the VPN without giving the Firewall the DNS server as its primary DNS provider.

The problem with the DNS server being the primary provider, is that the internet traffic will be routed through the VPN.

I need the Internet traffic to be separate from the VPN traffic and still allow for VPN traffic to have DNS resolution. I feel this may be a NAT issue, or possibly a rule/policy problem. I can't seem to get a straight answer anywhere.  

Any ideas? 



This thread was automatically locked due to age.

Top Replies

  • Based on your description, your internet traffic is not being routed via the VPN that has the DNS server on it, just the DNS queries.

    Here is how to deal with this issue. Configure your DNS as you normally would using ISP, public, or whatever DNS server you want to use for your Internet DNS queries. Then configure a "DNS request route" with the domain name you need the remote office to query. The target is the DNS server you want for the internal DNS queries.

    Configuring this will use your standard DNS configuration for all DNS queries, except for the domain you configured the DNS request route.

    This is located at Network > DNS then at the bottom of the menu is DNS host entry.

    The one issue I have found out about this I am uncertain how or why the Sophos uses a particular interface to make the requests to the DNS request route. It seems to choose one randomly, so you may have to do some log or packet captures to determine what interface is making the requests of your DNS server via the VPN. 

    Resulting DNS request map.

    Jump to answer
Parents Reply Children
No Data