Okay, not thinking straight anymore. After moving client to XG tonight form Cisco ASA external DNS is failing. Their internal authoritative DNS server has private IPs for the host names, and with the ASA they'd respond to a DNS lookup as their NAT'd public IPs, and everything was happy. I realized with the XG that the lookups now get the private IP, and mail can't come in. DNSSTUFF test against the domain says no MX record. Put the ASA back in line and the DNS tests pass and mail resumes. Am I missing something stupid, or what was the ASA doing that I need to replicate? Alternatively, is there a way to make the XG do what Sonicwall calls a loopback, where an internal host can access an internal resource by its public IP because the Sonicwall will bounce it back in to the private? I used that a lot with Sonicwalls.
This thread was automatically locked due to age.