cancel
Showing results for 
Search instead for 
Did you mean: 

Split DNS

Here to help

Split DNS

Hola Meraki Community!

 

I'm upgrading a remote site from a Barracuda firewall to an MX64.  Now, this site currently has a "DNS Service" install on the Barracuda to split DNS.  This remote site has it's PCs domain joined (hence the current setup).  On the MX how am I able to do this (if necessary) to have normal internet requests go through ISP DNS, and only AD requests through the VPN tunnel?

9 REPLIES
Highlighted
Kind of a big deal

Re: Split DNS

You can't do this on Meraki.

Here to help

Re: Split DNS

What would be "best practice" then so users can authenticate?  I typically setup IPsec tunnels, but don't want ALL their traffic flowing through the VPN.

Head in the Cloud

Re: Split DNS

You just need to do split-tunneling then on the MX
 
Internet traffic goes out local, and traffic destined for 'internal' will go over the VPN.
 
DNS that you provide that subnet with should be internal DNS only if you want to ensure internal sites resolve.
 
See example below
 
 
 
5555.jpg
Nolan Herring | nolanwifi.com
TwitterLinkedIn
Here to help

Re: Split DNS

Thanks for the image.  My only issue here is our corporate firewall is not Meraki, it's Barracuda.  So when I select Spoke, I have no option of manually creating the hub.  Under Organization-Wide Settings I do have the Non Meraki Peer created.

Kind of a big deal

Re: Split DNS

@jdsilva is correct.  You should direct all your DNS requests to the AD servers.  The actual web browsing and the like will still go out the local circuit.

Here to help

Re: Split DNS

So for the subnet that requires this, manually set the DNS to our AD Servers under the DHCP settings of that subnet, correct?

Head in the Cloud

Re: Split DNS

Correct. If your MX is handling DHCP/DNS, then make sure you have your AD/internal servers placed there because it will go over the VPN and allow internal sites to resolve.

If you put one internal and one public, your going to have issues so don't do that
Nolan Herring | nolanwifi.com
TwitterLinkedIn
Here to help

Re: Split DNS

Thanks for all the help everyone!