This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG DNS request route (internal dns forward)

Hello together,

we have a problem with the dns request route configuration. We have multiple remote sites and a datacenter. The datacenter has a ad/dc with dns function. The clients in the remote site sends the dns requests to the Sophos XG 85/105/115 firewall. The firewall have a vpn connection to the datacenter and want to send the request for the datacenter domain to the datacenter sophos xg firewall.

We have added the following entry: Network -> DNS: Name: xxx.local

      Target: xx.xx.xx.xx (ad/dc ip)

This forward is not working. Have you an idea what the problem is ?



This thread was automatically locked due to age.
Parents Reply Children
  • Hello DanSand,

    Luk is right and I will try to explain why.

    The current version of XG Firewall does not have correctly implemented (against UTM v9) DNS Request Route feature. All DNS requests are forwarded to DNS servers to the Internet regardless of the setting for the DNS Request Route. And the second very import feature that is implemented in XG Firewall is an internal NAT for IPSec site-to-site VPN tunnels. These are two reasons why Kranthi advises to you to use those two commands in the device console.

    We can only hope that these bugs in the current version will be corrected in the version v2.

    I hope that Kranthi agree with me?

    alda


    P.S.

    Please see to next link from Copernicus Partner Preview where I dealt with them

    community.sophos.com/.../57844