Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

External DNS Query IssueDNS

Hi,

I have a cPanel Server with Bind Name Server behind the firewall with many hosting domains inside, websites, emails, ftp, etc.

All services work correctly doing NAT with the required ports. The only problem is the DNS server (BIND). I do NAT of port 53 TCP/UDP, but external DNS querys never come to pass the firewall, never reach their destination, which is the internal cPanel Server with Bind as Name Server.

Anyone can help me please? It's a critical service for our hosting domains.



This thread was automatically locked due to age.
Parents
  • Javier,

    go to Administration > Device Access and enable DNZ on WAN Zone. Use ACL (inside the same meny) ti deny certain remote hosts/networks.

    Thanks

  • Hi,

    I enabled DNS in Device Access, and I has NATTED ports 53 in TCP/UDP, nut when i try to make external nslookup i get: DNS Request Time Out.

     

    This has to be a public DNS (ns2.ardanet-systems.com) when i make the nslookup in ns1.ardanet-systems.com (another public IP) i get the correct result, the query works fine, but no in the sophos xg (ns2.ardanet-systems.com)

     

    for example:

    nslookup ark-servers.online ns1.ardanet-systems.com  (That is NATTED with a simple IPTABLES... works like a charm)

    nslookup ark-servers.online ns2.ardanet-systems.com (That is NATTED with Sophos XG... DNS Request Time Out)

     

    Any idea?

     

    Thx for all

Reply
  • Hi,

    I enabled DNS in Device Access, and I has NATTED ports 53 in TCP/UDP, nut when i try to make external nslookup i get: DNS Request Time Out.

     

    This has to be a public DNS (ns2.ardanet-systems.com) when i make the nslookup in ns1.ardanet-systems.com (another public IP) i get the correct result, the query works fine, but no in the sophos xg (ns2.ardanet-systems.com)

     

    for example:

    nslookup ark-servers.online ns1.ardanet-systems.com  (That is NATTED with a simple IPTABLES... works like a charm)

    nslookup ark-servers.online ns2.ardanet-systems.com (That is NATTED with Sophos XG... DNS Request Time Out)

     

    Any idea?

     

    Thx for all

Children