Why Management interface do query instead of DNS-Proxy Interface

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Why Management interface do query instead of DNS-Proxy Interface

 

Hi Team,

I configured DNS proxy Interface e1/1 - 192.168.29.245 to clientless vpn.

DNS-Proxy resolves as,

  1. General browsing resolves with DNS 8.8.8.8 and 1.1.1.1
  2. Tutelartechlabs.com resolves with DNS 1.1.1.2 and 4.4.4.4
  3. Amazon.forest.in (internal-application) resolves with DNS 172.30.30.31

LC1.jpg

 

LC2.jpgLC3.jpgLC4.jpg

Note:

DNS-Proxy interface is the interface that act as a proxy and queries for dataplane traffic instead of management interface setup-->service-->DNS.

so the question is why my management interface 192.168.29.250 queries for amazon.forest.in to the DNS server when the application is accessed by a user in clientless-vpn  instead of my DNS-Proxy Interface 192.168.29.245.

I have attached both pcaps from server and the firewall.

 

LC5.jpgLC6.jpg

1 REPLY 1

L6 Presenter

If you have correctly also attached the DNS proxy under the "Proxy" tab in the Clientless VPN then it could be a bug because you have the managment ip address in the same subnet as the data interface and I think that there was such an issue but I can't say for 100%.

 

Test if also configuring the service route for DNS to use the data plane interface will help or if possible to place the data plane interface in seperate subnet than the managment interface.

 

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/service-routes

  • 1269 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!