We have 2 MX100's (Primary and secondary) and both have been showing the DNS misconfigured alert for about a week. A packet capture shows that DNS requests on both WAN uplinks are not getting responses. We can see them going out but there is never a response back. Most of our internal traffic is routed through a site to site VPN to AWS where it goes out through a firewall. All of these internal VLANs do not have any connectivity problems. Our guest network which does not travel over the site-to-site VPN has been down since the error appeared.
The change log shows no changes at the time that the misconfiguration first occurred.
We have tried changing the DNS servers used on both uplinks with no effect.
Meraki support recommended checking with our ISP to figure out why we are not getting DNS responses. We have done that but they have been less than helpful.
Does anyone have any ideas of what could be going on? Has anyone had experience with an ISP blocking DNS responses?
I am happy to answer any additional questions. Help is greatly appreciated.