Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

OpenVPN DNS issue

Hi there,

I have built a new VPN configuration for SSL VPN but I have troubles with name resolution.

We have a split DNS with the same DNS suffix existing inside and outside out network.

The connection comes up, nslookup hostname.our-domain.de queries the internal DNS server and gives back an IP. So far so good.

But when I ping that IP or use RDP the Windows clients tries to connect to an external IP because our domain-name also exists in the WWW. This doesn't make sense to me because nslookup works.

The gateway metrik of the sophos default route is higher than the route metrik for the wlan gateway - that's my problem. For testing purposes I used a metrik >500 on the WLAN adapter, reconnected and now everything works and th eclient always queries the internal DNS.

But that's not a solution because I don't want to mess up the metrik settings in our corporate network.

Is there a way to set the metrik to 1 through the sophos appliance or the VPN-client?

Thanks and regards

Marcel



This thread was automatically locked due to age.
Parents
  • Hi Marcel,

    "But when I ping that IP or use RDP the Windows clients tries to connect to an external IP"

    I understand that you are trying this from the outside when connected via VPN - correct?

    • In 'Remote Access >> Advanced', do you have either your internal DNS or the UTM configured as the first DNS server?
    • If the UTM is one of the DNS servers, is "VPN Pool (SSL)" in 'Allowed Networks' in 'DNS'?
    • Please compare your overall setup with DNS best practice.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi Marcel,

    "But when I ping that IP or use RDP the Windows clients tries to connect to an external IP"

    I understand that you are trying this from the outside when connected via VPN - correct?

    • In 'Remote Access >> Advanced', do you have either your internal DNS or the UTM configured as the first DNS server?
    • If the UTM is one of the DNS servers, is "VPN Pool (SSL)" in 'Allowed Networks' in 'DNS'?
    • Please compare your overall setup with DNS best practice.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children