Hi Forum,
we have the problem with the following scenario:
- SITE A:
* primary ns server for domain
* ASG-120 gateway with 5.200
* dynamic IP
* DNS proxy for Site A LAN
- SITE B:
* secondary ns server for comain
* ASL with 5.203
* fix IP
* DNS proxy for Site B LAn
* DNAT rules for DNS service from internet to NS-server in LAN
* SNAT rules for DNS service from NS-server in LAN to internet servers, mapping this traffic to another ip than our MASQ-internet.
What works:
* RSA net-to-net VPN
* nearly all tested services working (RDP, HTTP, HTTPS, ...)
* any service allowed in both directions on both sites
The problem:
! NS traffic is not going through the VPN
Description:
Every NS-traffic-packet which should enter the tunnel seems to leave the Site B Astaro but not arriving at Site A Astaro.
I see "allowed" entries in the LiveLog on Site B which says there is UDP traffic on port 53 from secondary ns server to primary ns server.
But I dont see any log entry in the LoveLog of Site A which prints _ANY_ incoming packet! This is also the same if I drop any traffic between both sites and log this, there is also no "deny" log.
Thats why I think that there is some conflict with any other rule, nat-rule or config on site b, because it seems that the packet is really not going INTO the tunnel as no such packet is coming out on Site A).
Does anybody has a hint or experiences with such an conflict?!?!?
Thanks a lot,
Matthias Eichler
This thread was automatically locked due to age.
. If it is a typo, it would be a greate feature request
.