DNS rewrite matching wrong NAT rule

Showing results for 
Show  only  | Search instead for 
Did you mean: 

DNS rewrite matching wrong NAT rule

L1 Bithead

Think this needs a case.  Open to any suggested workarounds.


Connecting two overlapping networks with NAT.  (why? we have to)  (zone1) --  PA --  (zone2)

policy routing in place, come in zone1 interface go out zone2 and vice versa

Doing network nats at a /24 in this example


If I do two rules, natting the overlapping network to the same - ie symmetrical nat -  DNS rewrite works: 

src: to (zone2) - dest: to DNS rewrite - reverse

src: to (zone1) - dest: to DNS rewrite - reverse

both networks will towards the firewall - firewall has policy routes.

All is good, dns requests get fixed up in either direction correctly.

traffic passes correctly


If I nat to a different network in each direction, then only the first hit matches, its as if the DNS rewrite is matching on first ip address match only and ignoring the zone.   This fails to match on direction, and returns the wrong DNS rewrite entry for the second rule

src: to (zone2) - dest: to DNS rewrite - reverse

src: to (zone1) - dest: to DNS rewrite - reverse

zone1 network has a route towards firewall

zone2 network has a route towards the firewall

firewall runs policy routing


in this example, a server in Zone1 does a DNS request to a NS in Zone2, the response is correctly rewritten to 10.1.1.x

But in the other direction, the DNS answer should be 10.1.2.x but its getting matched on the NAT rule in the wrong direction


If I flip the order of the rules, the problem is that only the first destination nat is matching dns rewrite even though direction is wrong


Anyone else have this issue or know of a workaround - or why dns rewrite is not matching with zone context?


L1 Bithead

We are running 9.0.4


In the second scenario where the DNS rewrite does not work, the traffic passes fine.  It just that the NAT rules are smart enough to have zone context and it appears the DNS rewrite does not.


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!