Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: DNS A/AAAA no response from Proxy

$
0
0

Hi Vikas,

 

Will do but first let me repeat, on the client when I force IPv4 only i.e. request just an 'A' record then the Proxy _DOES_ work.

 

It is only when the client makes a request for an 'A' record followed straight away by the request for the 'AAAA' record that it fails. 

 

You can see this in the log, I added a line saying 'below here it works' showing the proxy response to the client that doesn't happen as part of the 'dual' request.

 

I've added a couple of screen grabs from Wireshark showing the A/AAAA request and lack of response and then the -4 IPv4 only request and the proxy response.

 

ssg-1.slaytor.com(M)-> get config | in "dns proxy"
set dns proxy
set dns proxy enable
ssg-1.slaytor.com(M)-> get config | in "server-select"
set dns server-select domain * outgoing-interface ethernet0/8.10 primary-server 8.8.8.8 secondary-server 4.4.4.4 failover

ssg-1.slaytor.com(M)-> get dns host settings
DNS Server:
Primary : 8.8.8.8, Src Interface: ethernet0/8.10
Secondary: 4.4.4.4, Src Interface: ethernet0/8.10
Tertiary : 0.0.0.0, Src Interface: Null

Refresh domain name IP Addresses:
Every day at: 06:28 o'clock
Last performed look-up: 11/30/2017 06:28:08
Next scheduled look-up: 12/01/2017 06:28:00

Normal UDP session: 0

 

ssg-1.slaytor.com(M)-> get dns server-select
usage: 1/32
--------------------------------------------------------------------------------
* [static]
Server IP: Interface: ethernet0/8.10 Failover : [enabled]
|--> 8.8.8.8 [static]
|--> 4.4.4.4 [static]
|--> 0.0.0.0
--------------------------------------------------------------------------------


ssg-1.slaytor.com(M)-> get dns proxy
state: enable usage: 0/32 [no record :0 timeout 1939 no server 1953]
current client list:
--------------------------------------------------------------------------------
Client IP Port Domain name Type Sock State Age
--------------------------------------------------------------------------------
No pending client requests
ssg-1.slaytor.com(M)->

 

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>