- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello guys,
I'm pretty new when it Comes to VSX deployments and the related VS configuration. I have a quite Basic setup with one VSX cluster consisting out of two physical devices. On top of the VSX cluster we have two VS running (VS #1 and #2). Each VS has two dedicated interfaces. So currently there is not virtual switch or router in place, as there was no need for VS-to-VS communication or shared interfaces.
Now to my issue:
Basically I just want each VS to use a different DNS server, as per default the DNS config (as well as some other GAiA paramaters) are getting synched from VS0. The issue is, that once a change in clish of VS2 is made (regarding DNS) this is also getting synched to all the other VS (including VS0). So basically I assume that there is not way to have a different dns server entries for each VS...? I found a SK that mentions this problem and offers a solution - but this is only related for the remote access vpn blade and can't be used by any other feature. Without the possibility of configuring one or multiple different dns Servers for each VS I do not see a way to get any updates or the proxy feature working, as the gateway itself needs to send dns queries here.
It is also not wanted to have a shared dns in this environment as each VS should work completely independent from the other. So even if I adjust the routing so that VS2 can reach the DNS of VS0 no solution is met.
I read the VSX admin guide and could not find any word regarding this issue - so it could be the case that I overlooked something. Hopefully someone can point me in the right direction. 🙂
Regards,
Maik
Maik,
the system is working as expected, by design the DNS configuration is shared beetween all VSs, see DNS configuration of a single VS affects all other VSs too
You can change the DNS-server for the MOB-blade only following All Virtual Systems on VSX Gateway / VSX cluster with enabled Mobile Access blade are trying to reac...
Wolfgang
Hello Wolfgang,
Thanks for your reply. Yes, I my guess was that it works by design like I described.
I am just wondering if there is any way to do it differently? I mean, why should I keep everything seperate from each VS but not the DNS settings (to mention one example, which is related to this thread). Does this mean that I need to specify several DNS servers so that all are getting synched while only one is applicable per vs? I have the requirement to separate DNS strictly - thus not allowing VS2 to access the same DNS as VS1 or VS0.
The only "solution" I can think of is specifying three dns servers, that are getting synched to all VS in my Environment:
- Primary [for VS0]
- secondary [for VS1]
- tertiary [for VS2]
But this would lead to failing DNS requests each time VS1 or VS2 try to do a name resolution… so this is not really a solution but just a very dirty Workaround (that would also eliminate redunancy per VS dns, as I would have only one dns Server per vs).
Maik,
I understand your problem and you are not alone. But it is how it works.
If you have requirements to separate the DNS, then VSX maybee is not a solution or you have to accept the limitation.
Maybe some of the other VSX guys here has an idea or maybe with R80.30 is something new ?
Wolfgang
*push*
Some words from the community would be great - maybe someone already had this issue in the past and solved it via some way?
NAT or BIND Views might help as work arounds.
Hi Maik,
Were you able to get this resolve in your infrastructure or a workaround. I am in the same boat and just noticed the same thing when i tried to setup dns.
Thanks
"Domain objects for example require dns queries", this is one example. Also per business requirement all company assets should have the ability to be queried by there hostname.
Similar to your environment i have 3 VS which separates my infrastructure domain. In essence there are three dns servers respectively.
Did anything ever come of this?
I have a use case where I need a VS to be completely isolated from the corporate network to support guest wireless. This network is completely self contained and has dedicated DNS servers.
I need to either be able to have separate DNS servers per VS or the ability for a given VS to pipe DNS queries over a management plane to VS0 so it can do the DNS lookup work.
@Tommy_Forrest @with R81 and up it‘s possible to configure DNS per VS
Configuring DNS Servers on a Virtual System „set dns mode per-vs“
Hot diggite dog! You just made my day.
Set it up and it's working.
For those playing along with the home game, enabling per-vs mode will wipe out the DNS configs in your other VSen so be sure to go back and reset them if you turn this on.
Hey @Tommy_Forrest and others.
To be clear - what happens when I enable this feature?
Will each existing VS no longer have DNS servers set, until I define it locally on the VS?
If they copy over the 'old' global dns server - will that now be reached from the local interface on an existing VS?
/Henrik
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY