Excluding Certain Domain Names Did Not Succeed

|
  • 331
  • 6

Issue Description

By adding a domain name at Global Exclusion, the release of www.sangfor.com.cn does not take effect.

Handling Process

Obtain the network topology: the intranet DNS server filled in by the DNS of the computer, and the IP of the DNS server added to the Global Exclusion.

Root Cause

The principle of Global Exclusion is that IAM does not do any processing on the IP in the list, and IAM will analyze the DNS packets to obtain the real IP address of the domain name.
Because the DNS of the computer points to the intranet DNS server, the DNS packets are all sent to the external DNS by the intranet DNS server.
However, the IP address of the intranet DNS is added to the IAM’s Global Exclusion, so the DNS reverse resolution function does not take effect.

Solution

Remove the DNS server’s IP address from Global Exclusion.

Suggestions

If the data of the intranet DNS server does not pass the IAM, it is recommended to configure the DNS as the intranet DNS on the IAM. Otherwise, the Global Exclusion domain name will not take effect.
Faisal Posted 25 Aug 2020 08:12
  
Thank you very much for the information ...
Faisal Posted 19 Oct 2020 12:08
  
Nice article ...
Faisal Posted 22 Dec 2020 07:15
  
Great info ...
Ellechar Lv4Posted 20 Jan 2021 15:44
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 23 Mar 2021 12:40
  
Very informative …
Faisal Posted 08 Jun 2021 17:19
  
Nice guidance ...

I want to write a case
Doc ID: 2508
Author: Newbie1212
Updated: 2019-12-21 12:53
Version: