SPlit DNS resolution

Status
Not open for further replies.

gregory.b

Silver Partner
Basic Certified
Joined
Sep 28, 2020
Messages
101
Reaction score
6
Dear All,

I have a client on Premises Installed.
3CX is already in Version 20 as we are forced to upgrade so quickly.

Upgrade was successful,

However, it seems that the Client has a Meraki as main interface for his routing and configuration.
Am having an issue with the SPLIT DNS. His Domain controller add his local domain at the end of the FQDN when he tried to add it.

Then resulting to a failure and his Mobile Application are not working within his local Network wish is a big big Issue.

Note that we can't migrate to Hosted by 3CX as in our country we don't have those kind of SIP Trunk that can connect to Internet. And a Gateway will be way to much complication and not as per client needs.

Any ideas how i can resolved this Split DNS issue on Meraki.
 
What is doing DNS? The domain controller? Than its easy to do split dns. When the dns add his local domain behind the fqdn than he is doing something wrong.
 
Dear All,

I have a client on Premises Installed.
3CX is already in Version 20 as we are forced to upgrade so quickly.

Upgrade was successful,

However, it seems that the Client has a Meraki as main interface for his routing and configuration.
Am having an issue with the SPLIT DNS. His Domain controller add his local domain at the end of the FQDN when he tried to add it.

Then resulting to a failure and his Mobile Application are not working within his local Network wish is a big big Issue.

Note that we can't migrate to Hosted by 3CX as in our country we don't have those kind of SIP Trunk that can connect to Internet. And a Gateway will be way to much complication and not as per client needs.

Any ideas how i can resolved this Split DNS issue on Meraki.
You need to create a new zone on his AD DNS server.
 
  • Like
Reactions: bitn2
What is doing DNS? The domain controller? Than its easy to do split dns. When the dns add his local domain behind the fqdn than he is doing something wrong.
Its domain Controller
 
  • Like
Reactions: bitn2
You need to create a new zone on his AD DNS server.
Can you explain further please so i can advise
Thank you for the reply
 
Can you explain further please so i can advise
Thank you for the reply
On your AD server in DNS management , you need to create a zone that matches your external 3cx domain. SO that you then maintain a zone outside and inside your organisation. The external zone points to your external IP address and the internal points to the servers internal IP address.
 
  • Like
Reactions: gregory.b
  • Like
Reactions: gregory.b
IM USING 3CX.COM AS AN EXAMPLE IN THIS POST. PLEASE DO NOT USE 3CX.COM IN YOUR ACTUAL DEPLOYMENT. USE THE 3CX DOMAIN THAT IS IN USE BY YOUR PBX!!!

Lets say your PBX has an FQDN of pbx.3cx.com

Your public IP address is 100.150.200.250

Your PBX has an SSL certificate that secures pbx.3cx.com

All clients connecting from outside the network are allowed through the firewall to connect to the PBX. As the certificate is assigned to pbx.3cx.com and this is what the devices requested, the connection is allowed to proceed.

Now, on the internal network, the internal devices need to go to the PBX, but its internal iP Address is 192.168.0.10

As the devices will make a DNS request to the 3CX DNS server, as this is the authoritative DNS server, it will respond with 100.150.200.250.

If your firewall does not allow a hairpin redirection (loopback etc) then this connection will be dropped.

So we need to find a way to redirect the internal devices making a request to pbx.3cx.com to go connect to 192.168.0.10

This is where your internal DNS server comes into play. It will have a DNS zone for 3cx.com which has an A record for pbx.3cx.com that points to 192.168.0.10 and NOT 100.150.200.250.

That way with the same SSL certificate you have a valid connection, both internally and externally.
 
  • Like
Reactions: gregory.b and bitn2
It will have a DNS zone for 3cx.com which has an A record for pbx.3cx.com that points to
Normally, and for sure on Windows Server, one can create a zone for pbx.3cx.com directly, which lets other *.3cx.com names resolve normally.
 
Why would any other host need to resolve 3cx.com sites internally? Would someone try to replicate our services? Essentially it would be a 1 host DNS zone for the PBX specifically. We do not allow the 3cx.com domain to be used by the general public for this reason.
 
Okay the client can't seems to do so as he doesn't have AD Server And they cannot create a DNS Record outside there domain name. As there MXrecord will resolve pbx.3cx.com.domain name


Thus, i have another idea.
Will it work if i edit the Host File on the 3CX Linux ?
https://www.redhat.com/sysadmin/configure-hostname-linux
Using this guide.

Can it be an alternative way to resolve the issue even if its not conventional. I just want to know it can has the possibility to work.
 
Your internal DNS server is where the changes need to happen. What is your DNS server?

Otherwise you could try Hairpin NAT if your router supports it.
 
Why would any other host need to resolve 3cx.com sites internally? Would someone try to replicate our services? Essentially it would be a 1 host DNS zone for the PBX specifically. We do not allow the 3cx.com domain to be used by the general public for this reason.
I was echoing the example above. Not overriding the entire ny.3cx.us domain would allow theoretical connections to PBXclient2.ny.3cx.us. A Talk link for example.

@gregory.b You need each client, including mobile apps on wireless, to resolve the hostname internally. You’d need to edit the hosts file on everything.
 
Your internal DNS server is where the changes need to happen. What is your DNS server?

Otherwise you could try Hairpin NAT if your router supports it.
I don't know there DNS Server.
I know they use Meraki
 
You will need to investigate this.
 
Status
Not open for further replies.

Forum statistics

Threads
111,953
Messages
589,909
Members
164,845
Latest member
tdzski5