Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
siddu099
Participant

DNS NOT RESLOVING

Hi Experts,

 

 

I am using checkpoint 81.20 jumbo 99 
dns is not resolving 
ping 8.8.8.8 is working
ping google.com not resolving

show dns primary
8.8.8.8


show dns mode
default

0 Kudos
8 Replies
the_rock
Legend
Legend

Maybe try quad 9 dns, 9.9.9.9 or 149.112.112.112

Whats output of curl_cli -k google.com?

Andy

0 Kudos
siddu099
Participant

Hi Team,

 

I am not getting any response for

curl_cli -k google.com

also cant able to ping 9.9.9.9

 

 

ping 9.9.9.9

 

PING 9.9.9.9 (9.9.9.9) 56(84) bytes of data.

^C

--- 9.9.9.9 ping statistics ---

2 packets transmitted, 0 received, 100% packet loss, time 999ms

0 Kudos
the_rock
Legend
Legend

Do constant ping to 9.9.9.9 in one window and in the other one fw ctz zdebug + drop | grep 9.9.9.9

0 Kudos
siddu099
Participant

Hi Rock,

After adding the static route we can able to ping the dns 
but we are using the x.x.x.x/29 in bgp 
still we are facing the issue to ping some of public-ip


0 Kudos
Chris_Atkinson
Employee Employee
Employee

How does the Gateway receive it's default route, do you see it in the route table?

CCSM R77/R80/ELITE
0 Kudos
Chris_Atkinson
Employee Employee
Employee

What's the underlying platform, any other NSG / NACLs that might need adjusting?

CCSM R77/R80/ELITE
0 Kudos
siddu099
Participant

Hi Chris,

Its running on ESXI environment 
we configured bgp in checkpoint 
there is know restriction ACL for outgoing and incoming

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Please ensure that you've followed sk101214 if this is a cluster on ESXi.

Can you please share the routing table, do you see the routes with "netstat -rn" or "ip route"?

 

CCSM R77/R80/ELITE

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.