[strongSwan] Local bind9 DNS server fails when connected to remote gateway
sms at icefire.qza.net.au
Sat Oct 22 22:28:58 CEST 2016
I have a local file/dhcp/dns server (bob) which sits behind a 4g nat and connects via ipsec tunnel to a vps gateway (bill) and routes all traffic over the internet.
This works fine if the clients behind bob use an external dns for name resolution. This isn't practical however, since I run a local instance of bind9 that serves requests for both external and internal domains.
This works fine, until I connect the tunnel, at which point I can see the clients sending requests to bob, and bind9 logs show it doing the queries, but the response never appears in wireshark and the client hangs. Queries originating from bob still work however.
bob: Debian 8
leftid=bob at my.net
rightid=skyline at qza.net.au
load_modular = yes
install_routes = no
I've been poking at this for a couple of days now, I'm stumped as to what's going on.
Maerkis <sms at icefire.qza.net.au>
More information about the Users