12-18-2017 04:24 PM
Hi,
Do you know if DNS Proxy is supported on Eth1 via NAC?
The reason this is required is that we have a Guest wireless bridged directly out the second interface on a pair of wireless controllers to a a dedicated DMZ network for Guest internet traffic only.
Currently we have a pair of NAC appliances whom Eth1 interfaces are in the Guest DMZ network.
Currently I have this working by redirecting to Captive Portal using controller based redirect with the redirect URL pointing to the IP address of one of the NAC appliances.
The reason I have to change this to DNS proxy is that although I have some load balancers available that would support fail-over to either of the NAC's, these do not have direct access to the internal DNS servers in the DMZ network to resolve any URLs I send to them.
With the use of the Load Balancers I just need to configure the controller based redirect to point to a single URL that points to the load balancers, which in turn resolves to either of the NAC devices (via an internal DNS) dependant on which NAC is available.
The problem I have is that in this particular case I'm not able to plum in the DNS directly into the DMZ network so I have nothing to resolve too, so will need to be reliant on DNS Proxy.
Have confiugred DNS proxy as per the following GTAC article:
https://extremeportal.force.com/ExtrArticleDetail?an=000079035
If I connect to the Guest Wireless I don't get redirected to captive portal, although if I put in the IP address of the NAC device in the client you get the captive portal.
In addition if I put in a URL it does get resolved to the correct IP instead of the NACs, so just seems to be a problem with DNS proxy not doing its job and replacing the IP address of the URL with NAC's instead to display the captive portal page.
My concern is that I need an option on the Eth1 interface that is greyed out, as per below:
This is a summary of my wireless rules:
Wireless controller is running version 10.41.01.0082
NAC / Netsight is running version 8.0.3.46
Many thanks in advance
12-20-2017 03:18 AM
12-19-2017 08:00 AM
12-19-2017 07:22 AM
12-19-2017 07:14 AM
Hi Martin,
Please check below KB for basic debug about DNS proxy issue in NAC.
https://extremeportal.force.com/ExtrArticleDetail?an=000080258
also just make sure eth1 is enabled in NAC interface configuration.
https://extremeportal.force.com/ExtrArticleDetail?an=000078313
Thanks,
Suresh.B