07-29-2021 10:15 AM - edited 07-29-2021 10:16 AM
Hi,
I'm configurering a Group Policy for RA VPN in Firepower FTD and I'm trying to understand the different options for DNS split tunneling in the group policys.
I thought that the option "Send DNS requests as per split tunnel policy", would only route dns request to internal domains, but it seams like AnyConnect uses the internal DNS servers for all request as long as those DNS servers are configured in the Group Policy . Is that correct? If so, I don't really seem the need for the other option "Always send DNS requests over tunnel".
Can someone maybe give a brief explanation on what those different DNS Request Split Tunneling options does?
Thanks
Chess
Thanks
07-29-2021 10:18 AM
07-29-2021 10:36 AM
Thanks, but I cannot find any explanation on the different DNS spilt tunneling options there.
07-29-2021 06:54 PM
07-29-2021 07:56 PM - edited 07-29-2021 08:08 PM
I've seen that explanation in the official Cisco documentation, but is the first option - Send DNS Request as per split tunnel policy - that confuses me. When testing this in my lab with a split tunneling Group Policy, all DNS request was sent to the internal DNS server configured in the group policy.
The only time it choose the DNS servers I got from my ISP, was when I shut down the internal DNS server.
nslookup didn't work at all, but I could still reach other domains, using my ISP assigned DNS servers.
So my conclusion is that this option works as a fallback in case the internal DNS servers are not reachable.
/Chess
07-30-2021 01:56 AM - edited 07-30-2021 01:58 AM
So my conclusion is that this option works as a fallback in case the internal DNS servers are not reachable.
There is no fallback here, the policy is strict as per splitting policy (i do not believe there is dynamic mechanism here,)
Other hand how will Local DNS information available on Public domains ? example business.local username.local.
Most organisation have 2-4 DNS Servers, so the dns lookup take place round robin, so if all down, service down thats all. (that will be wider problem in business, never seen that case, if that happends its P1 issue).
08-02-2021 10:59 AM
I have the same question. Our Split DNS is blocking internet bound requests for some people and not for others.
If the Split Tunnel is defined by an Access List and the Access List contains only IP addresses, then how does the Send DNS Request as per split tunnel policy option know which requests to send to the internal DNS servers? The Send only specified domains over tunnel option makes perfect sense.
Thanks
11-03-2023 12:14 PM
You are correct the access-list contains only IP addresses and so the DNS requests will go over the tunnel if the IP address of the DNS server is in the split tunnel access list and not over the tunnel if the dns server ip address is not in the access list.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide