Dear Board Members,
since about 3 days our DNS service in our network is going crazy.
First, we have a Windows Server 2008 R2 domain controller (DC) where the DNS Server in configured as a DNS Forwarder to the Astaro Firewall. So clients first send their DNS requests to the DC then it gets redirected to the Astaro Firewall and then to the DNS servers of our provider.
The DNS service of the Astaro Firewall is configured that it only allows DNS requests from the DC. And there are 2 DNS forwarding entries for DNS servers of our providers. Regarding DNS service there is no rule in the packet filter rules.
Since 2 days erratically DNS requests from the DC by the Astaro packet filter gets dropped (-> packet filter log). So our DNS system is sometimes working sometimes not and I can't find the reason why this is happening. Astaro worked well for about 4 months and this suddenly started to happen.
Additional Information:
Prior to the problems above an additional interface with an additional subnet was connected (this is a test subnetwork with test clients), a few new packet filter entries were made for the new subnet and the subnet was added as an allowed network to make DNS requests to astaro.
Our Astaro Firewall:
Astaro Virtual Appliance on VMware ESXi with license for 25 users / Astaro Version 8.102
This thread was automatically locked due to age.