VPN does not support DNS

Created: Oct 10, 2019 05:49:48Latest reply: Oct 10, 2019 09:02:59 209 4 0 0
  Rewarded Hi-coins: 0 (problem resolved)

Hello experts, our customer got a problem and needed your help.

The customer got a USG6600 firewall, it is failed to update the signature online. It is successful to ping the IP of the website(sec.huawei.com) on the firewall, but failed to ping the URL from the firewall.

When pinging the URL on the firewall, an error 'VPN does not support' DNS occurred.

<huawei>ping -vpn-instance PUB_ISP_vod sec.huawei.com

Error: VPN does not support DNS.

It would be appreciated for any suggestions.


  • x
  • convention:

Featured Answers
chenhui
Admin Created Oct 10, 2019 08:17:51 Helpful(0) Helpful(0)

Posted by user_3445655 at 2019-10-10 07:24 Yes, the interface is bind to the vpn-instance PUB_ISP_vod
Well, you are kindly advised to check the dns resolve configuration and routes of the dns server.
VPN-instance doesn’t support encapsulate the DNS packet, so there should be a route to direct the DNS packets from the public instance to the vpn-instance. Please refer the configuration below:
update host source ip x.x.x.x vpn-instance PUB_ISP_vod
dns server vpn-instance PUB_ISP_vod
dns resolve
dns server 1.1.1.1
ip route-static 1.1.1.1 32 vpn-instance PUB_ISP_vod x.x.x.x
  • x
  • convention:

All Answers
chenhui
chenhui Admin Created Oct 10, 2019 05:51:41 Helpful(0) Helpful(0)

Hello, does the interface which connects to the ISP bind to the vpn-instance?
  • x
  • convention:

user_3445655
user_3445655 Created Oct 10, 2019 07:24:16 Helpful(0) Helpful(0)

Posted by chenhui at 2019-10-10 05:51 Hello, does the interface which connects to the ISP bind to the vpn-instance?
Yes, the interface is bind to the vpn-instance PUB_ISP_vod
  • x
  • convention:

chenhui
chenhui Admin Created Oct 10, 2019 08:17:51 Helpful(0) Helpful(0)

Posted by user_3445655 at 2019-10-10 07:24 Yes, the interface is bind to the vpn-instance PUB_ISP_vod
Well, you are kindly advised to check the dns resolve configuration and routes of the dns server.
VPN-instance doesn’t support encapsulate the DNS packet, so there should be a route to direct the DNS packets from the public instance to the vpn-instance. Please refer the configuration below:
update host source ip x.x.x.x vpn-instance PUB_ISP_vod
dns server vpn-instance PUB_ISP_vod
dns resolve
dns server 1.1.1.1
ip route-static 1.1.1.1 32 vpn-instance PUB_ISP_vod x.x.x.x
  • x
  • convention:

user_3445655
user_3445655 Created Oct 10, 2019 09:02:59 Helpful(0) Helpful(0)

Posted by chenhui at 2019-10-10 08:17 Well, you are kindly advised to check the dns resolve configuration and routes of the dns server.V ...
ok, I'll try that.
  • x
  • convention:

Comment

Reply
You need to log in to reply to the post Login | Register

Notice Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!
Login and enjoy all the member benefits

Login and enjoy all the member benefits

Login