v20 Split-DNS/Hairpin NAT

Status
Not open for further replies.

whiteym

Gold Partner
Advanced Certified
Joined
Apr 16, 2020
Messages
23
Reaction score
9
Hi All,
Few things I've noticed so far with v20;
  • The doco https://www.3cx.com/docs/creating-fqdn-split-dns/ says that Split DNS, NAT Loopback and Hairpin NAT are the same thing. This should be changed as they aren't, NAT Loopback and Hairpin NAT are the same thing but Split-DNS is different.
  • I have recently configured a client on v20 with hairpin NAT using their Watchguard. I followed the guide, however only a single internal phone can register at a time using the DNS name. Subsequent phones try to register but they get no response from the phone system.
    To resolve the issue I have changed the phones to use the internal IP to register the phones.
Will there be any on-going issues with the phones registering against the system IP? Re the requirement for DNS is that only for the app's to function or will that also affect phones at some point?
 
Split DNS is a reuirement for v20. If Hairpin Nat isnt working you need to use Split DNS. With your firewall this should be no problem.
 
Our recommendarion is to implement Split DNS within the network.

We have allowed the registration of phone to the IP address, but this may change in the future.

Also, the NAT loopback can be used when someone does not have the capabilities of installing an internal DNS server.
 
  • Like
Reactions: Evolute IT
@bitn2 I would, except Watchguards are dumb and don't have a DNS server in them. We are in the process of replacing them but the phones need to go in first.

@NicholasP_3CX thanks, I figured it would break at some point in the future. I'll just make a note that we can't use hairpin NAT on Watchguards.
 
@bitn2 I would, except Watchguards are dumb and don't have a DNS server in them. We are in the process of replacing them but the phones need to go in first.

@NicholasP_3CX thanks, I figured it would break at some point in the future. I'll just make a note that we can't use hairpin NAT on Watchguards.
Has NAT Loopback been tested and confirmed to be a problem with Watchguard? I have a few sites with Watchguard, and I don't want to force the clients to add or maintain a DNS server they don't want for any reason other than that someone said it didn't work for them. This thread implies it doesn't work, yet the documentation still shows it as a solution. Looking for clarity!
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,953
Messages
589,917
Members
164,851
Latest member
DrunkeMeister