• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Azure to pfSense IPSec Tunnel - DNS issues

Scheduled Pinned Locked Moved IPsec
4 Posts 2 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    Netronidus
    last edited by Mar 27, 2014, 1:36 PM

    I have a real puzzler and I cannot seem to figure it out.  I'm hoping there is someone who might offer suggestions.

    First, separate question:

    My IPSec tunnel between my pfSense box and Azure box seems to go down with no activity after awhile.  As the configuration options on the Azure side are limited, does anyone have a solution on this?

    Now, for the real issue:

    I have a working VPN tunnel between my local network and Azure.  From an Azure machine, I can ping items on my local network.  However, DNS doesn't function at all.  Here is a basic setup:

    Local Network
    DNS Server: 10.10.218.5
    OS: Server 2008 R2 Enterprise
    All firewall profiles are disabled

    Azure Network
    Local server: 172.16.0.4
    Looks to local network for DNS.
    OS: Server 2012 Datacenter
    All firewall profiles are disabled

    Both systems can ping each other successfully.  RDP functionality works fine.  File sharing works fine.  However, if I execute any DNS lookups from my Azure system to 10.10.218.5, they fail.  Utilizing NSLOOKUP, any queries will generate four "DNS request timed out" and obviously fail.  Now, the kicker is that from the Azure system, I can telnet to port 53 and get an answer successfully.

    Based on this, is this a problem with the tunnel or something in pfSense blocking?  Any bright ideas?

    1 Reply Last reply Reply Quote 0
    • N
      Netronidus
      last edited by Mar 28, 2014, 9:22 PM

      I should add that I don't believe this is isolated to Azure.  We have a second IPSec tunnel as well from another site with different hardware and it too cannot resolve DNS across the tunnel.  Again, any feedback you all can supply would be really helpful.  Thanks!

      1 Reply Last reply Reply Quote 0
      • T
        thermo
        last edited by Mar 29, 2014, 9:15 PM

        Odd thing you mentioned is that telnet is tcp whereas dns is udp port 53….

        1 Reply Last reply Reply Quote 0
        • N
          Netronidus
          last edited by Mar 30, 2014, 4:41 PM

          …and with that response, I honestly figured it out.  Sheesh!  Why didn't I remember to allow UDP across my tunnel?  DNS works fine now.  Thanks!

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received