Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS bug in Multi-Wan 2.3.1_5

    Scheduled Pinned Locked Moved Routing and Multi WAN
    13 Posts 4 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kapara
      last edited by

      See attached.  When  switching to AT&T no one is able to resolve.    When the land gateway is used as the DNS.  I have tried switching the DNS for AT&T to Google DNS and several others but with no resolve

      image.png_thumb
      image.png

      Skype ID:  Marinhd

      1 Reply Last reply Reply Quote 0
      • dotdashD
        dotdash
        last edited by

        Looks ok, but I'd switch so you had comcast/att/comcast/att. I forget if they go in order or query in parallel. If you are running DNS on the firewall, I'd hand out the gateway IP, but you could try handing out google DNS via DHCP.

        1 Reply Last reply Reply Quote 0
        • K
          kapara
          last edited by

          Problem is we have domain coming in to the picture.  I will try.  Thanks

          Skype ID:  Marinhd

          1 Reply Last reply Reply Quote 0
          • K
            kapara
            last edited by

            The more I look at this it seems like a bug as i have followed the documentation.

            Skype ID:  Marinhd

            1 Reply Last reply Reply Quote 0
            • dotdashD
              dotdash
              last edited by

              If you have a domain, then it's easy- serve dhcp and dns from the AD controllers. I don't think it's a bug though, I've done failover using the firewall for dns and dhcp. As long as I have one dns server going out each wan, the clients can resolve when the primary line is down.

              1 Reply Last reply Reply Quote 0
              • K
                kapara
                last edited by

                not alway an option as some are remote offices with no DC so I use local dns and DNS forwarder for the domain

                Skype ID:  Marinhd

                1 Reply Last reply Reply Quote 0
                • K
                  kapara
                  last edited by

                  i have tried every possible scenario.  This looks like a bug.  I have 2 DNS configured on each gateway yet still unable to resolve when switching to backup connection.  if same DNS is hard coded into PC not to use the gateway for DNS resolution then machines are able to resolve.  Using gateway as DNS does not work on failover gateway.  Even the pfSense firewall is unable to resolve when switched to ATT.  Client machines are able to resolve when 8.8.8.8 or 4.2.2.2 are manually entered but those DNS on the ATT interface DNS under general are not.

                  Skype ID:  Marinhd

                  1 Reply Last reply Reply Quote 0
                  • K
                    kapara
                    last edited by

                    Disabled DNS Resolver and enabled DNS Forwarder.  Not sure if there is a special requirement with DNS Resolver but it was preventing the secondary connection from resolving and I have not seen any documentation requiring special modification to DNS Resolver settings.

                    Skype ID:  Marinhd

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      By default, the DNS Resolver talks directly to the roots and can only do so over the default gateway. With the DNS Resolver you need to make adjustments for Multi-WAN, one of two scenarios:

                      • Activate Default Gateway Switching (System > Advanced, Miscellaneous tab)

                      -or-

                      • Enable Forwarding mode in DNS Resolver so it respects the DNS servers under System > General
                      • Disable DNSSEC unless you know for certain the forwarding DNS servers support DNSSEC

                      The second scenario causes it to behave similar to the DNS Forwarder.

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • L
                        luisocr
                        last edited by

                        Awesome. Thanks for the clarification, I was having the exact same problem, until I looked at the documents

                        Forwarding mode is necessary for Multi-WAN configurations unless default gateway switching is enabled.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.