Community discussions

MikroTik App
 
Shabehemoth
just joined
Topic Author
Posts: 2
Joined: Mon Mar 18, 2024 11:10 am

Conditional DNS Forwarding breaking IPSec - Possible Bug

Mon Apr 15, 2024 4:25 pm

Hi

I had an issue the past few days where a site would not establish an IPSec tunnel after reboot.
I eventually narrowed it down to DNS.
The tunnel uses a peer FQDN: vpn.domain.com
The router has 2 static DNS FWD entries:
/ip dns static add forward-to=1.1.1.1 name=vpn.domain.com type=FWD
/ip dns static add forward-to=10.56.53.26 match-subdomain=yes name=domain.com type=FWD
On reboot the tunnel does not establish with these entries enabled.
If I disable both and reboot the tunnel establishes.
If I enable either, then the tunnel does not establish.

I created a workaround by running a script on startup to wait 10 seconds and then to disable and reenable the IPSec peer.

Who is online

Users browsing this forum: No registered users and 6 guests