DNS resolution fails with FORMERR after upgrading to 12.3 or 12.4

Description

The DNS resolution fails over the connect tunnel client or from the AMC lookup feature

Cause

DNS query sent from the SMA device adds the addition EDNS header and this change was made from February 2019 after the DNS flag day update.


After February 1st 2019 major public DNS resolver operators will disable/stop accommodating work around for standards non-compliance responses and will start accepting DNS packets with EDNS extensions under the additional records

Resolution

DNS packages on the SonicWall SMA devices have been updated to accommodate DNS requests with the additional resource records and this change was mainly for the GTO services. This ensures that the SMA appliances under GTO service remain responsive to EDNS queries.

                      This also affected any query made to the internal DNS server, as an appliance on 12.3 or 12.4 sends a DNS query with additional records to the internal DNS server. If the internal server is not capable of handling DNS packets with additional records, it responds back with a "format error".

Image


Below image is the request from SMA appliance to the DNS server,

Image

Windows server 2008 or 2012 might not handle DNS requests with EDNS records and DNS cookies, this is because EDNS or DNSSEC might note be enabled on the server.

Image

Steps to fix this issue, Run the below command on windows server and enable DNSSEC on the DNS management properties,


--> dnscmd /config/enableednsprobes 1


Image


For more details about DNS flag day, please refer the below link


https://dnsflagday.net/2019/


Related Articles

  • How to Provision SMA1000 in Monthly Billing (MSSP Program)
    Read More
  • SMA 1000 Series Support Matrix
    Read More
  • How to Configure SAML 2.0 SSO with Microsoft Entra ID for SonicWall SMA 1000 Series
    Read More
not finding your answers?