MX67 seems can't resolve DNS

Solved
RHA057
New here

MX67 seems can't resolve DNS

Hi everyone,

We get an issue while trying to reach some websites. In the firewall rule if we set , for example 
protocol    source      src prt        destination                    dest port
any             any             any            *.teamviewer.com            any
It doesn't work but if we set the ip for the destination instead of url than we can reach teamviewer domain
We are using a MX67 (19.1.9). We don't have this issue with our mx85.....We re going mad lol

Any help will be appreciated 

Thanks

1 Accepted Solution
ww
Kind of a big deal
Kind of a big deal

Did you try using the fw log tool. Filter on the client and start the update or whatever you are testing.  It could indicate what rules are blocking what traffic.

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Firewall_Logging

View solution in original post

9 Replies 9
Mloraditch
Kind of a big deal
Kind of a big deal

What exactly are you trying to do? Block teamviewer.com, allow it? and if allow it, what are you overriding, a more restrictive firewall rule? content filtering??

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
RHA057
New here

hi mate,


We are simulating a user access. Their computer will only have access to windows update or withsecure antivir updates. Computers can update on the meraki mx85 but not on the mx67. So we try to access teamviewer by url and ip. Because when we do a tracert command we can't go further than the mx67 (its local ip), it s like the mx67 can't resolve the url of teamviewer (an example for us to understand what's going on) BUT if in the firewall rule we put the ip , no problem anymore.
Only difference is in content filtering cause we got some ad, exchange etc behind the mx 85 
Layer 7 are the same , only few layer 3 rules are different but we don's figure out which one can occur the problem

Mloraditch
Kind of a big deal
Kind of a big deal

So you are trying to allow access to teamviewer? If so you want to review the documentation on FQDN rules: https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings#FQDN_Support

I suspect teamviewer may use a bunch of different hosts and servers and the way the MX does DNS snooping it may not be catching everything needed.

Have you tried calling support? Since they can see your config, it should be fairly simple to troubleshoot with them and narrow down what the issue is.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
RHA057
New here

Our first issue the initial one was to update withsecure signatures...It doesn't work....so we try with teamviewer but the issue is systemic ....I have to wait till next monday to have the approval to call directly cisco .

ww
Kind of a big deal
Kind of a big deal

Did you try using the fw log tool. Filter on the client and start the update or whatever you are testing.  It could indicate what rules are blocking what traffic.

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Firewall_Logging

RHA057
New here

We try and we see nothing in the log....really nothing

PhilipDAth
Kind of a big deal
Kind of a big deal

The * in the destination is invalid.  Change it to:

teamviewer.com

This does all sub-domains automatically.

RHA057
New here

We put both to be sure...nothing change. We did a hard reboot last night, same problem this morning.

RHA057
New here

Yes we see now we have to modify a rule "group" 10....

Get notified when there are additional replies to this discussion.