VPN clients cannot access router for DNS
Posted: Tue Apr 24, 2018 5:38 am
Hi, new user here.
Device is an RB2011UiAS-2HnD-IN.
Firmware and O/S have been updates to the latest stable versions available.
I have no problems getting my VPN clients (IOS right now) to connect (via l2tp/IPsec), and everything works great so long as I don't use my router's IP address for the DNS server address under the profile I've created. If I use 8.8.8.8, it works great. If I change that to my router's IP (192.168.10.254), it won't work, nothing resolves. All the machines on my LAN are able to use 192.168.10.254 for DNS.
For grins, I did momentarily disabled the default firewall rule "drop all not coming from LAN," and then I can use the router's IP address for my DNS. Of course, I re-enabled that right away.
I think I need a firewall rule above the "drop al not coming from LAN" so DNS (53 tcp) can make it through to the router, but I'm not sure how to proceed, or if this is the correct approach.
Any tips?
Thanks in advance, BTW. This router is AWESOME! I'm having a blast learning about it.
Device is an RB2011UiAS-2HnD-IN.
Firmware and O/S have been updates to the latest stable versions available.
I have no problems getting my VPN clients (IOS right now) to connect (via l2tp/IPsec), and everything works great so long as I don't use my router's IP address for the DNS server address under the profile I've created. If I use 8.8.8.8, it works great. If I change that to my router's IP (192.168.10.254), it won't work, nothing resolves. All the machines on my LAN are able to use 192.168.10.254 for DNS.
For grins, I did momentarily disabled the default firewall rule "drop all not coming from LAN," and then I can use the router's IP address for my DNS. Of course, I re-enabled that right away.
I think I need a firewall rule above the "drop al not coming from LAN" so DNS (53 tcp) can make it through to the router, but I'm not sure how to proceed, or if this is the correct approach.
Any tips?
Thanks in advance, BTW. This router is AWESOME! I'm having a blast learning about it.