02-10-2021 03:44 AM
Hi,
we are getting the below events on expressway -e
2021-02-10T14:26:14.648+03:00 traffic_server[7829]: Event="Sending HTTP error response" Status="403" Reason="Forbidden" Dst-ip="104.128.83.98" Dst-port="37247" UTCTime="2021-02-10 11:26:14,648"
2021-02-10T14:26:14.648+03:00 traffic_server[7829]: Event="get_edge_sso" Detail="Access denied" Reason="MRA not supported" Domain="domainname.com" Src-ip="104.128.83.98" Src-port="37247" UTCTime="2021-02-10 11:26:14,648"
on jabber getting the below error
"you cannot login outside corporation
cwa just rotating
The device there is no change, the certificate is internal ,but it was working
Thanks
Solved! Go to Solution.
02-11-2021 09:23 AM
What @Nithin Eluvathingal is asking you is if your A record for the E in the internal DNS is setup with the IP address of the internal network interface on the E? That’s what the C is communicating with, so that’s what it has to resolve.
02-11-2021 09:36 AM
Hi,
Yes , A record for E is the internel IP of E
Thanks
02-11-2021 04:32 PM
Hi,
if you have configured everything as @Nithin Eluvathingal mentioned below reply. Please do a flush dns on the expressway c and perform reboot on both expressway servers
regards
Shalid
02-11-2021 09:39 AM - edited 02-11-2021 09:40 AM
Below should be the configuration since you are using the Dual Nic.
Internal DNS Enteries:-
Certificates
Public DNS.
02-12-2021 08:23 AM
Hi ,
I tried to capture the dns traffic , this is what I am getting .
02-12-2021 09:46 AM - edited 02-13-2021 03:21 AM
The DNS server is responding that the A record is not found. This is where I would recommend you to start looking.
02-12-2021 10:15 AM
You said your domain is single domain , But from the logs I see vcse.mycomany.com and your DC in mycomany.local. is this a single domain environment ? what's your expressway C and ipt serve domain and what is your outside domain ?
I recommend you to read the design guide shared.
test.com (intenal) hosted internal
test.com (external) hosted at ISP
02-12-2021 11:28 AM
test.com is a zone in the test .local
So if anyone tries to resolve vcse.mycompany.com.tl from inside, it will resolve local IP ( that is 192.168.3.100)
so you can say both outside and inside the domain is the same mycompany.com.tl
if anyone tries the same it will resolve public IP
here is the problem I mentioned in previous posts.
1) I tested with dnsutility from Expressway-C , it can bring the IP address of any FQDN (regardless internal and external except the Expressway-E
2) I did " nslookup vcse.mycompany.com.tl" from multiple computers, all got replies from DC01( Which is the internal DNS server )
what I mean here there is no issue with the DNS
3) I did flushdns on Expressway-C
Thanks
02-12-2021 12:26 PM
Do the C use the same DNS server(s) as the computer where you have tested the name resolution from?
02-12-2021 06:32 PM - edited 02-12-2021 06:33 PM
Whats the Domain name of Expressway C is this mycompany.local?
As @Roger Kallberg mentioned on expressway C, is it using the same DNS as the PC you are able to resolve the Express-E ?
02-13-2021 01:37 AM
Hi,
vcsc.mycompany.com.tl this is the fqdn of expressway-C.
.local and forward lookup zone is a common deployment scenario in windows active directory deployment
usually there will be a .local default zone and forward lookup zone
for example cnn.local and cnn.com in same Domain name server (in my case the IP is 192.168.100.10 )
so a user try to resolve an fqdn, pc will send to the same server 192.168.100.10
Do the C use the same DNS server(s) as the computer where you have tested the name resolution from?
Yes
Thanks
02-13-2021 02:19 AM
@susim wrote:
Do the C use the same DNS server(s) as the computer where you have tested the name resolution from?
Yes
Thanks
Then I have no more ideas. For sure something in you setup is at fault, as the packet capture shows that the name query for the FQDN of the E from the C is resulting in A record not found.
I know you have written before that it's a A record, but are you 100% sure that you do not use a CNAME or Host record in the DNS and that the value you have put in the C and E for the traversal zone is the A record? Would you mind to take screenshots of these records, C and E, in DNS and also of the traversal zone configuration in both E and C and not masking the names? If you absolute want to mask it, would it be possible that you just change out the domain part so that the rest is visible and untouched?
02-13-2021 02:54 AM
Asper your reply your vcse.mycompany.com.tl should resolve to 192.168.3.100 and your DC ip is 192.168.100.10 the screenshot you shared when expressway C trying to resolve vcse.mycompany.com.tl has 192.168.3.100 And 192.168.100.10.
So 192.168.3.100 is this expressway E or C ? have you configured proper entry on DNS ?
Do you have forward and reverse entry for vcse.mycompany.com.tl in your DC ?
02-13-2021 03:34 AM
Hi
192.168.3.100 VCSC and 192.168.100.10 is the domain name server, 3.100 sending a query to resolve vcse.mycompany.com.tl
and 192.168.100.10 replying back that I don't know vcse
it is not cname ,it is A record
can I send you in private all the screenshot .
Thanks
02-13-2021 04:00 AM
That would work for me. I’ll have a look at it once you send me the PM.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide