01-26-2022 10:47 AM
02-07-2022 01:11 PM
The DNS you configure in the network policy is for aps, the dns used by clients is configured by dhcp server, so if you are sending guest clients to a different dhcp server then perhaps their dns configuration is different. If you are using a device as a guest dhcp server client, Extreme Networks devices that are DHCP clients can receive a domain name and DNS server IP address through DHCP, although any DNS settings that you enter as part of the network policy dns configuration override those that are dynamically applied.
Finally, I would consider if you are applying an ip firewall on the guest network, our default ip firewall object is configured to specifically allow dns traffic but a custom one might not have that allowance included.
02-01-2022 11:18 AM
Following on from James's point, I presume that you're using a DHCP server that's external to the AP (which is providing the clients with the DNS server address)?
If you connect to the Corp SSID, which DNS server(s) are assigned to the client? Then with the guest, is it using the same DNS server as corp or another? If the same, is it reachable via ping?
Thoughts being
- different DNS servers being given out in the DHCP option, of which the guest DNS server is unreachable.
- Both using the same DNS server, but is unreachable on the guest VLAN (presuming they're different between SSIDs)
Also, if you set a manual DNS server on a client e.g. 8.8.8.8 does it then work as you'd expect?
01-26-2022 11:31 AM
01-26-2022 11:27 AM