NetScaler DNS Resolution Issue Through Full VPN When ISP has IPv6 Activated

NetScaler DNS Resolution Issue Through Full VPN When ISP has IPv6 Activated

book

Article ID: CTX205087

calendar_today

Updated On:

Description

DNS resolution issue after connecting to NetScaler Gateway using VPN plug-in. The issue only occurs if the internet service provider has IPv6 activated. If the provider has only IPv4 this works without issues.

For testing upgraded the NetScaler to 11.0 and not seeing this issue.

If a client connects over NetScaler SSL VPN, IPv6 DNS server is received. Then when resolving any internal Host with the FQDN we get an error that the domain does not exist.

With NetScaler Gateway 11.0 setup, after connecting to the VPN we see an IPv4 DNS server. It seems the VPN plug-in over writes the DNS with IPV4 address i.e 10.0.0.1. This does not happen with 10.5.

Resolution

This issue is fixed as part of the following bug (snippet from release notes), which is fixed in NetScaler Gateway 11.0 and 10.5-58.11:
With IIP and Split Tunnel on, the local machine's network is configured as part of the intranet application, and DNS queries fail on Windows machines. [# 558156, 552774]

To resolve this issue upgrade to NetScaler 10.5-58.11.

Issue/Introduction

DNS resolution issue after connecting to NetScaler Gateway using VPN plug-in. The issue only occurs if the internet service provider has IPv6 activated. If the provider has only IPv4 this works without issues.