• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

2.3.5 DNS Suffix no longer working With Shrewsoft

Scheduled Pinned Locked Moved IPsec
1 Posts 1 Posters 310 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    RobEmery
    last edited by Apr 12, 2018, 3:16 PM

    Hello,

    We've just upgraded our in-office firewalls to 2.3.5 and we've found that clients using ShrewsoftVPN no longer have
    a working DNS suffix provided to them.

    I've run the shrewsoft tracetool on the clients and I can see a difference in the attributes that are pulled:

    Working (2.2.6)

    
    18/04/12 16:04:22 ii : received config pull response
    18/04/12 16:04:22 ii : - IP4 Address = 192.168.254.2
    18/04/12 16:04:22 ii : - IP4 DNS Server = 10.3.0.10
    18/04/12 16:04:22 ii : - IP4 DNS Server = 10.3.0.11
    18/04/12 16:04:22 ii : - Unkown VARIABLE 13 = 8 bytes
    18/04/12 16:04:22 ii : - DNS Suffix = ourdomain.internal
    18/04/12 16:04:22 ii : - Split Domain
    18/04/12 16:04:22 ii : - IP4 Split Network Include = ANY:10.3.0.0/24:*
    
    

    Not Working (2.3.5)

    
    18/04/12 16:00:52 ii : received config pull response
    18/04/12 16:00:52 ii : - IP4 Address = 192.168.2545.2
    18/04/12 16:00:52 ii : - IP4 DNS Server = 10.3.0.10
    18/04/12 16:00:52 ii : - IP4 DNS Server = 10.3.0.11
    18/04/12 16:00:52 ii : - IP4 Subnet = ANY:10.3.0.0/24:*
    18/04/12 16:00:52 ii : - Unkown VARIABLE 28676 = 8 bytes
    18/04/12 16:00:52 ii : - Unkown VARIABLE 28674 = 18 bytes
    18/04/12 16:00:52 ii : - Unkown VARIABLE 28675 = 18 bytes
    18/04/12 16:00:52 ii : - Unkown VARIABLE 28673 = 1 bytes
    
    

    I've looked at the config files in /var/etc/ipsec/strongswan.conf between both versions and they both have:

    
            plugins {
                    attr {
                            dns = 10.3.0.10,10.3.0.11
                            subnet = 10.3.0.0/24
                            split-include = 10.3.0.0/24
                            # Search domain and default domain
                            28674 = "ourdomain.internal"
                            28675 = "ourdomain.internal"
                    }
    
    

    This is with the same version of shrewsoft etc, the only difference is the version of PFSense.

    Any thoughts?

    Thanks,
    Rob

    1 Reply Last reply Reply Quote 0
    1 out of 1
    • First post
      1/1
      Last post
    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
      This community forum collects and processes your personal information.
      consent.not_received