cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
775
Views
0
Helpful
2
Replies

ASA DHCP DNS

alan-wong
Level 1
Level 1

Dear

I am running site to site VPN from site B to site A

site A: 192.168.1.1/24

site B: 192.168.2.1/24

On siteB. I used following DNS in site B DHCP from 5505 ASA.

dhcpd dns 192.168.1.1 202.66.192.68

When the site to site tunnel is working.  It is normal DNS requests from site B to site A DNS.  however, if the site to site tunnel is disconnected, site B not able to request site A DNS and do not jump to second DNS 202.66.192.68.

Can anyone help to resolve.  I want siteB can use secondary DNS: 202.66.192.68 when tunnel is not connected.  Thank you

Alan.

1 Accepted Solution

Accepted Solutions

Mariusz Bochen
Level 1
Level 1

Hi Alan,

The fact that you're disconnecting your VPN makes me think you don't need a permanent connectivity, so maybe is better idea to setup remote client VPNs and configure the dns-server as VPN group-policy attribute? It gives more DNS flexibility, split-dns feature and so on. Not sure what is the exact requirement, but I don't think the stuff you're trying to achieve is durable with l2l VPN.

Regards

Mariusz

View solution in original post

2 Replies 2

Mariusz Bochen
Level 1
Level 1

Hi Alan,

The fact that you're disconnecting your VPN makes me think you don't need a permanent connectivity, so maybe is better idea to setup remote client VPNs and configure the dns-server as VPN group-policy attribute? It gives more DNS flexibility, split-dns feature and so on. Not sure what is the exact requirement, but I don't think the stuff you're trying to achieve is durable with l2l VPN.

Regards

Mariusz

Dear Mariusz

I would like to know is that possible to jump from Primary DNS to Secondary DNS in case VPN tunnel disconnected by any accidentially reason?

Regards

Alan.