Support Support Downloads Knowledge Base Apex Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

[ScreenOS] Proxy DNS feature fails when loopback interface is used as outgoing-interface

0

0

Article ID: KB10419 KB Last Updated: 11 Aug 2010Version: 3.0
Summary:
If loopback IP address is used as outgoing-interface in Proxy DNS configuration, a specific route to the DNS server needs to be configured on the loopback interface.
Symptoms:
In a route-based VPN scenario, IP address of the loopback interface might be used as the outgoing-interface for Proxy DNS feature as it is the only routable IP address inside the VPN tunnel, but simply specifying loopback address of outgoing interface in Proxy DNS setting is not sufficient.
Solution:
In order for   set dns server-select domain DOMAIN.NAME outgoing-interface loopback.1 primary-server IP_address_of_internal_name   to function properly, it needs to have route of the IP_address_of_internal_name server on loopback interface.

Example:
set interface loopback.1 ip 172.30.1.1/32
set dns host dns1 10.10.10.10 src-interface loopback.1
set dns server-select domain internal-domain.name outgoing-interface loopback.1 primary-server 10.10.10.10

set route 10.10.1.101/32 gateway 172.30.1.1


Please note that Proxy DNS feature will not work when used with policy based VPN KB3680

Related Links

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search