DNS resolution fails with FORMERR after upgrading to 12.3 or 12.4

Description

The DNS resolution fails over the connect tunnel client or from the AMC lookup feature

Cause

DNS query sent from the SMA device adds the addition EDNS header and this change was made from February 2019 after the DNS flag day update.


After February 1st 2019 major public DNS resolver operators will disable/stop accommodating work around for standards non-compliance responses and will start accepting DNS packets with EDNS extensions under the additional records

Resolution

DNS packages on the SonicWall SMA devices have been updated to accommodate DNS requests with the additional resource records and this change was mainly for the GTO services. This ensures that the SMA appliances under GTO service remain responsive to EDNS queries.

                      This also affected any query made to the internal DNS server, as an appliance on 12.3 or 12.4 sends a DNS query with additional records to the internal DNS server. If the internal server is not capable of handling DNS packets with additional records, it responds back with a "format error".

Image


Below image is the request from SMA appliance to the DNS server,

Image

Windows server 2008 or 2012 might not handle DNS requests with EDNS records and DNS cookies, this is because EDNS or DNSSEC might note be enabled on the server.

Image

Steps to fix this issue, Run the below command on windows server and enable DNSSEC on the DNS management properties,


--> dnscmd /config/enableednsprobes 1


Image


For more details about DNS flag day, please refer the below link


https://dnsflagday.net/2019/


Related Articles

  • SMA100 End of Support No-Charge Replacement FAQ
    Read More
  • SMA1000: Post upgrade to 12.5.0 on AWS and Azure, we show the error Could not retrieve the DNS settings once we log in to AMC/CMS console
    Read More
  • Firmware version required to upgrade to version 12.5.0.
    Read More
not finding your answers?