Azure Virtual Network Gateway DNS lookup

%3CLINGO-SUB%20id%3D%22lingo-sub-2495559%22%20slang%3D%22en-US%22%3EAzure%20Virtual%20Network%20Gateway%20DNS%20lookup%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2495559%22%20slang%3D%22en-US%22%3E%3CP%3EMorning%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20in%20the%20midst%20of%20setting%20up%20an%20Azure%20Virtual%20Network%20Gateway%20and%20I%20have%20hopefully%2C%20a%20quick%20question.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20updated%20our%20VPN%20XML%20file%20but%20cannot%20work%20out%20what%20we%20need%20to%20add%20to%20allow%20DNS%20FQDN%20lookups%2C%20for%20example%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20ping%20product-sql%20then%20I%20get%20no%20response.%3C%2FP%3E%3CP%3EIf%20I%20ping%20product-sql.domain.com%20then%20I%20do%20get%20a%20response.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20DNS%20servers%20are%20specified%20in%20the%20profile%20and%20port%2053%20is%20allowed%20for%20lookups%20in%20our%20NSG.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Morning all,

 

We are in the midst of setting up an Azure Virtual Network Gateway and I have hopefully, a quick question.

 

We have updated our VPN XML file but cannot work out what we need to add to allow DNS FQDN lookups, for example:

 

If I ping product-sql then I get no response.

If I ping product-sql.domain.com then I do get a response.

 

Our DNS servers are specified in the profile and port 53 is allowed for lookups in our NSG.

1 Reply
I assume if you ping: 'product-sql.' #Include the dot, does it respond?

If that's the case, it looks like a lookup problem (Windows may be trying to add an invalid FQDN), the easiest way around it is use the FQDN for all your lookups, I've had to change drive mapping in the past for the site to site VPN's to use the FQDN.

You can also try this test: On the clients, under TCP/IP properties/Advanced/DNS, ensure that "Append primary and connection-specific DNS suffixes" is selected and also that "Append parent suffixes of the primary DNS suffix" is checked.