In this article
Internal resources such as shared drives, intranet sites, and domain controllers can become unreachable after deploying DNSFilter. The fix depends on the deployment type.
Why can't I access internal resources after deploying DNSFilter?
Incorrect local domain and resolver settings are often the cause. Without proper configuration, DNS queries meant for internal servers may be sent to external resolvers, leading to failed lookups and service disruptions.
Roaming Clients
Roaming Clients automatically detect the original DNS configuration before enforcing policies. For internal domains to bypass filtering, local domains and resolvers must be configured in the DNSFilter dashboard.
To configure local domains and resolvers for Roaming Clients:
- Add the required local domains to the Local Domains list in the DNSFilter dashboard.
- Specify local resolvers. Without them, local domains are still filtered.
- Verify the device is receiving the correct local DNS server via DHCP.
For all configuration options, see Direct internal resource traffic to local servers when using Roaming Clients. If local domains do not resolve to the expected resolver, confirm DHCP's DNS Search Suffix is configured correctly.
Windows Roaming Client v3.0 and higher
On Windows Roaming Client v3.0 and higher, test DNS PreCheck as an alternative to Classic local domain and resolver routing.
DNS PreCheck does not use dashboard-defined Local Domains or Local Resolvers. It sends internal queries directly to the DNS resolver already provided by the network or VPN. This can resolve internal DNS issues in environments where:
- Internal DNS suffixes are delivered reliably by DHCP or the VPN
- Local DNS servers are reachable from the device
- Local domain lists change frequently or are difficult to maintain
If switching to DNS PreCheck restores access, the issue was likely related to missing or incorrect local domain and resolver configuration in Classic DNS Filtering mode.
DNS Relay
Unlike Roaming Clients, the DNS Relay does not automatically detect internal resolvers and must be configured manually. Dashboard-configured Local Domains do not apply to the Relay; all local domain routing must be defined directly in relay.conf.
To configure local resolvers for the DNS Relay:
- Add the local resolver IP addresses in
relay.confto direct internal traffic correctly. -
Ensure
.localdomains are correctly forwarded.These are automatically routed, but all other internal domains must be explicitly specified.
- Test internal lookups using
resolve-dnsnameordigto confirm queries are being resolved by the correct DNS server.
For the relay.conf syntax and examples, see Direct internal resource traffic to local servers when using Relays.
Networks using split tunneling or multiple segments
In complex environments where VPNs, VLANs, or multiple subnets exist, additional considerations apply:
- Confirm that DNS settings allow queries to route to the appropriate local resolver
- If using a VPN, ensure DNS traffic for internal resources is tunneled correctly
- Consider setting up conditional forwarding if some domains require different resolvers
Final checks
If local DNS resolution issues persist, check the following:
- Firewall rules allow internal DNS queries to pass through
- Firewall EDNS0 settings are not blocking traffic
- Devices are correctly receiving local DNS settings via DHCP
- No conflicting settings override local resolution preferences
Comments
0 comments
Please sign in to leave a comment.