- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-13-2023 07:00 AM
If you have your internal clients setup to utilize the dns-proxy properly you shouldn't need to allow your clients access to internal DNS servers, which appears to be what you're doing from a brief glance at your configuration. The firewall will handle forwarding when required, the clients don't need access to those external providers.
It seems like your clients aren't actually configured to utilize the dns-proxy configured interface IPs based off of what you're reporting. I'd double check that your clients are actually sending DNS requests to the interfaces you have dns-proxy enabled on, and that DNS isn't setup to still resolve to the external providers.