Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

DNS across VPN tunnel?

Hey guys,

I've got two firewalls providing an IPSec tunnel between two offices. The tunnel is up and talking, and everything seems ok. However, some of the hosts on the remote network are encountering DNS issues. The DNS and AD domain servers are all on my local network, and the remote users connect to the domain across the tunnel. Here's the kicker though: not all users are having this issue. Some workstations are resolving DNS just fine, while others are not at all. It's not a caching issue, I've verified that the working PCs are actually communicating properly with the DNS servers while the others are not.

Is there anything specific that needs to happen on the firewalls to ensure DNS traffic? My tunnel ACLs are set to encrypt all IP traffic between the two subnets, and I've enabled sysopt connect permit-ipsec to allow the traversal of encrypted traffic.

Thanks!

1 ACCEPTED SOLUTION

Accepted Solutions
Bronze

Re: DNS across VPN tunnel?

Do the Pix's have licenses for the amount of devices behind them?

4 REPLIES

Re: DNS across VPN tunnel?

How are you testing DNS across the tunnel? Are you just trying to hit a web page on certain hosts, and some work, some don't?

HTH, John *** Please rate all useful posts ***
Bronze

Re: DNS across VPN tunnel?

Do the Pix's have licenses for the amount of devices behind them?

Community Member

Re: DNS across VPN tunnel?

In the course of debugging I saw a curious message...regarding dropped sessions due to exceeding the number of inside hosts. I am getting this resolved now. Thanks very much for the help, guys!

Bronze

Re: DNS across VPN tunnel?

The license was out then?

can you rate the post if it helped please?

448
Views
0
Helpful
4
Replies
CreatePlease to create content