Hello. I am trying to accomplish the following:
Here is my setup
MX100
MS390 all networks are L3 on the 390.
4 MR45 AP's off the 390.
I'm trying to use the MX outbound firewall to block DNS unless it is specifically pointed at the internal DNS. I created 4 outbound rules in order from 1st to last, 2 rules to allow DNS UDP/TCP out from my internal DNS servers, and 2 rules to block all TCP/UDP DNS from any to any, last rule is allow all.
This seems to be working fine, I can test when the rules are enabled, that I am only able to resolve DNS from our internal servers as desired. What is weird, is the summary pages for my MS and MR's, are all saying that DNS is not configured correctly shortly after I enable the rules. These devices are all getting Management IP's via DHCP, and the Management VLAN DHCP Server on the MS is configured with our internal DNS servers. I can see the right DNS IP's are being picked up on the summary page for each AP and the MS390. Not sure what is up, if its something with the FW rules all on the MX and I am doing all L3 at the MS390?