DNS Resolution Failure with SonicWALL Mobile Connect VPN and Domain Joined Computer

Hi Guys,

Was hoping someone can help me. I'm having this exact issue: https://support.software.dell.com/kb/sw13532 and the workarounds aren't working. Logged a case with SonicWALL and they referred me to log a case with Microsoft. So, before going down that lonely road, maybe someone has seen this before.

In short, when a workstation connects to the SonicWALL SSLVPN; DNS resolution to internal DNS servers via the VPN fail. If I dis join the computer from the domain, DNS resolution works fine via VPN. This only affects SonicWALL SSLVPN clients that are joined to the domain.

Any suggestions or hopefully a link to the Windows Update\Patch?

Thanks,

Jacques

June 1st, 2015 12:11pm

Some more specifics.

Dell SonicWALL NSA 220; 5.9.0.x Firmware

Windows 8.1 Pro; Fully patched

Dell Venue 11 Pro (5130-32Bit); Latest drivers, firmware and BIOS

Windows Server 2008 R2 Domain; Direct Access and DNSSec disabled

Free Windows Admin Tool Kit Click here and download it now
June 2nd, 2015 2:52am

Hi,

I'm not familiar with the mechanism of SonicWALL Mobile Connect VPN, but you may take a look of the following two links

http://serverfault.com/questions/356115/vpn-connection-causes-dns-to-use-wrong-dns-server

http://rdpfiles.com/2011/08/25/windows-vpn-client-and-local-dns-resolution/

NOTE This response contains a reference to a third party World Wide Web site. Microsoft is providing this information as a convenience to you. Microsoft does not control these sites and has not tested any software or information found on these sites.

Regards

June 2nd, 2015 9:48pm

Hi Yolanda,

Thanks for the response. :) I have checked out the links provided, but the issue I'm having is exactly the opposite. The SonicWALL Mobile Connect is part of the built in VPN providers in Windows 8.1.

When the domain joined workstation connects to the VPN, its looses its ability to resolve DNS queries from its VPN provided DNS server addresses. 

If i dis-join the workstation from the domain and connect to the VPN, the client can query its VPN provided DNS servers without issue.

As per the link in my initial post; there is an identified bug. I was hoping someone has a workaround or maybe someone knows the Microsoft KB for this issue as Dell could not provide me this. I'm busy with a large managed tablet deployment and remote VPN access via Dell SonicWALL SSLVPN is a requirement.

Regards

Jacques

Free Windows Admin Tool Kit Click here and download it now
June 3rd, 2015 2:35am

VPN connected domain-joined machine-- you can manually configure the DNS suffix for the IP address, launch network connections, find the VPN connection, properties, then scroll down to IPv4\Properties\Advanced\DNS.

another useful link http://www.isaserver.org/img/upl/vpnkitbeta2/dnsvpn.htm

June 8th, 2015 1:57am

VPN connected domain-joined machine-- you can manually configure the DNS suffix for the IP address, launch network connections, find the VPN connection, properties, then scroll down to IPv4\Properties\Advanced\DNS.

another useful link http://www.isaserver.org/img/upl/vpnkitbeta2/dnsvpn.htm

Free Windows Admin Tool Kit Click here and download it now
June 8th, 2015 5:55am

VPN connected domain-joined machine-- you can manually configure the DNS suffix for the IP address, launch network connections, find the VPN connection, properties, then scroll down to IPv4\Properties\Advanced\DNS.

another useful link http://www.isaserver.org/img/upl/vpnkitbeta2/dnsvpn.htm

June 8th, 2015 5:55am

VPN connected domain-joined machine-- you can manually configure the DNS suffix for the IP address, launch network connections, find the VPN connection, properties, then scroll down to IPv4\Properties\Advanced\DNS.

another useful link http://www.isaserver.org/img/upl/vpnkitbeta2/dnsvpn.htm

Free Windows Admin Tool Kit Click here and download it now
June 8th, 2015 5:55am

VPN connected domain-joined machine-- you can manually configure the DNS suffix for the IP address, launch network connections, find the VPN connection, properties, then scroll down to IPv4\Properties\Advanced\DNS.

another useful link http://www.isaserver.org/img/upl/vpnkitbeta2/dnsvpn.htm

June 8th, 2015 5:55am

VPN connected domain-joined machine-- you can manually configure the DNS suffix for the IP address, launch network connections, find the VPN connection, properties, then scroll down to IPv4\Properties\Advanced\DNS.

another useful link http://www.isaserver.org/img/upl/vpnkitbeta2/dnsvpn.htm

Free Windows Admin Tool Kit Click here and download it now
June 8th, 2015 5:55am

Hi jzmine,

I have tried your proposal but AFAIK you cannot specify DNS suffixes on VPN connections. The options are greyed out...

Jacques

June 25th, 2015 8:07am

Hello Jacques

Sorry to dig up this post, but I have exactly the same problem, and workaround doesn't work (sw13532)

Have find a solution about this problem ?

Thanks in advance to your answer

Damien

Free Windows Admin Tool Kit Click here and download it now
August 27th, 2015 10:37am

Hi Damien,

Sorry for the late reply, been swamped with project work.

Unfortunately no, I was not able to find a solution to this. I'm still waiting on Microsoft to release an update for this.

I'm using PPTP tunneling through the firewall until then. Not ideal, but what else? :(

Did you find anything?

Cheers

Jacques

September 11th, 2015 1:35am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics