NGAF SSL VPN DNS Suffix

addimasqi Lv2Posted 18 Mar 2020 20:26

I have some problems with the SSLVPN connection.  I will summarize the existing condition & configuration (just for an example) :

The application server in the LAN zone :
- IP Address: 10.10.0.150
- Hostname: application-portal
- Usually, users access with browser by typing the hostname in the browser address.

VPN configuration :
- gateway deployment mode
- local DNS10.10.0.13
- route and configuration I think is OK.

Result :
- usually, users access with browser by typing the hostname in the browser and we can't access it with the hostname.  When we access using the IP address is OK.
- The ping test to DNS server is OK, ping test to hostname application-portal not resolve. The ping test to the application-portal IP address is OK.
- nslookup to hostname not resolve. (nslookup application-portal)
- when we check nslookup with DNS suffix (application-portal.ourdnssuffix) the IP address is resolved.

So the conclusion from troubleshooting with our server engineer is, we must add DNS suffix to the virtual IP pool for SSL VPN.  Is that true?

For comparison, when we using SSL VPN from Watchguard, they have a configuration to add DNS suffix / domain name.  For Sangfor NGAF in SSL VPN local DNS configuration, we choose "client PC uses the above DNS Server (10.10.0.13) or local domain name resource (ourdnssuffix).  

By solving this question, you may help 718 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

I Can Help:

Change

Moderator on This Board

1
131
3

Started Topics

Followers

Follow

18
8
0

Started Topics

Followers

Follow

Board Leaders