External private IP addresses registering with DNS server

%3CLINGO-SUB%20id%3D%22lingo-sub-480709%22%20slang%3D%22en-US%22%3EExternal%20private%20IP%20addresses%20registering%20with%20DNS%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-480709%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20been%20trying%20to%20fine-tune%20our%20NIDS%20configuration%20(which%20predates%20my%20employment%20here)%20and%20more%20specifically%20trying%20to%20figure%20out%20why%20certain%20IP%20addresses%2Franges%20that%20we%20don't%20use%2C%20keep%20appearing%20in%20reports%2Flogs.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20think%20I've%20figured%20out%20the%20root%20cause%2C%20but%20I'm%20not%20sure%20of%20the%20best%20way%20to%20fix%20it%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20a%20number%20of%20remote%20users%20who%20connect%20to%20our%20network%20by%20VPN.%20As%20best%20I%20can%20tell%2C%20when%20their%20laptops%20connect%20to%20the%20network%2C%20they're%20sending%20updates%20to%20the%20DNS%20server%20running%20on%20the%20DC%20with%20both%20the%20IP%20address%20of%20their%20VPN%20interface%20(routable%20on%20our%20network)%20and%20their%20private%20IP%20address%20on%20their%20home%20LAN%20(obviously%20not%20routable)%20-%20if%20I%20do%20an%20nslookup%20on%20a%20domain%20machine%2C%20the%20DC%20returns%20two%20A%20records%2C%20one%20for%20each%20address.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20has%20a%20slight%20ripple%20effect%20through%20the%20network%20-%20which%20manifests%20mostly%20with%20Windows%20Update%20Delivery%20Optimization%2C%20where%20the%20peer%20discovery%20process%20frequently%20gets%20the%20non-routable%20private%20IP%20somehow%20and%20then%20tries%20to%20download%20Windows%20updates%20from%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELong%20story%20short%3A%20what%20is%20the%20best%20way%20to%20prevent%20VPN'ed%20machines%20from%20registering%20external%20private%20IP%20addresses%20with%20the%20DNS%20server%20running%20on%20the%20DC%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-480709%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDNS%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EManagement%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1389407%22%20slang%3D%22en-US%22%3ERe%3A%20External%20private%20IP%20addresses%20registering%20with%20DNS%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1389407%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20experiencing%20the%20exact%20same%20issue%2C%20please%20respond%20if%20you%20found%20a%20resolution%20to%20this%20issue.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1390079%22%20slang%3D%22en-US%22%3ERe%3A%20External%20private%20IP%20addresses%20registering%20with%20DNS%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1390079%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F667951%22%20target%3D%22_blank%22%3E%40Hohmaniacs1%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESadly%2C%20I%20have%20not.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1449826%22%20slang%3D%22en-US%22%3ERe%3A%20External%20private%20IP%20addresses%20registering%20with%20DNS%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1449826%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F667951%22%20target%3D%22_blank%22%3E%40Hohmaniacs1%3C%2FA%3E%26nbsp%3B%20Ditto!%26nbsp%3B%20I'm%20seeing%20their%20home%20LAN%20IP%20as%20well%20as%20their%20VPN%20IP.%26nbsp%3B%20This%20is%20totally%20strange.%26nbsp%3B%20I'm%20assuming%20it%20has%20something%20to%20do%20with%20our%20Firewall%20because%20when%20I%20connect%20in%20via%20Azure%20VPN%20instead%20of%20our%20default%20Firewall%20VPN%20no%20DNS%20record%20even%20shows%20up%20for%20my%20test%20device....%20now%20I%20have%202%20concerns.%26nbsp%3B%20Unable%20to%20reach%20an%20Azure%20connected%20client%20and%20having%20an%20unroutable%20LAN%20IP%20address%20in%20my%20DNS.%26nbsp%3B%20Weird.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1449834%22%20slang%3D%22en-US%22%3ERe%3A%20External%20private%20IP%20addresses%20registering%20with%20DNS%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1449834%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F693319%22%20target%3D%22_blank%22%3E%40AwiegJax%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20case%20open%20with%20Microsoft%2C%20will%20update%20when%20I%20hear%20anything.%20So%20far%20they%20have%20no%20clue.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1467898%22%20slang%3D%22en-US%22%3ERe%3A%20External%20private%20IP%20addresses%20registering%20with%20DNS%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1467898%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F667951%22%20target%3D%22_blank%22%3E%40Hohmaniacs1%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThink%20I%20may%20have%20found%20the%20cause%20of%20our%20VPN%20Endpoints%20forwarding%20their%20VPN%20IP%20as%20well%20as%20their%20home%20LAN%20IP%20in%20our%20internal%20DNS.%26nbsp%3B%20There%20was%20a%20IP%20Helper%20set%20in%20our%20Fortigate%20Firewall%20that%20was%20set%20to%20%22help%22%20DNS%20pass%20though.%26nbsp%3B%20After%20disabling%20it%20then%20connecting%20to%20VPN%20from%20my%20test%20machine%20I'm%20now%20only%20seeing%20the%20routable%20VPN%20IP%20address%20and%20not%20the%20Endpoints%20Home%20LAN%20IP%20address.%20I%20tried%20removing%20the%20invalid%20DNS%20entries%20but%20they%20slowly%20show%20back%20up%2C%20it%20appears%20this%20setting%20may%20require%20an%20endpoint%20to%20disconnect%20and%20then%20reconnect%20in%20order%20to%20be%20applied.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3EDunno%20if%20that%20will%20help%20your%20situation%20but%20that%20appears%20to%20be%20what%20was%20causing%20our%20DNS%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECorrection%3A%20This%20did%20not%20resolve%20our%20DNS%20issue%20for%20remote%20clients.%20I'm%20leaving%20that%20up%20as%20an%20idea%20for%20others%20but%20I%20did%20finally%20find%20out%20what%20is%20causing%20it.%26nbsp%3B%20If%20a%20user%20connects%20from%20home%20and%20is%20hardwaired%20and%20connected%20via%20WiFi%2C%20they%20then%20connect%20to%20VPN%20and%20the%20tunnel%20utlizes%20one%20adapter.%26nbsp%3B%20The%20adapter%20it%20isn't%20using%20is%20the%20IP%20address%20of%20the%20device%20that%20gets%20added%20to%20our%20DNS.%26nbsp%3B%20The%20Local%20LAN%20IP%20address%20of%20the%20adapter%20VPN%20is%20utilizing%20is%20NOT%20added%20to%20our%20DNS.%26nbsp%3B%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EI've%20still%20yet%20to%20find%20a%20solution%20to%20this%20other%20then%20disabling%20the%20WiFi%20adapters%20or%20disabling%20the%20%22Register%20this%20connection's%20address%20in%20DNS%22.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1490886%22%20slang%3D%22en-US%22%3ERe%3A%20External%20private%20IP%20addresses%20registering%20with%20DNS%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1490886%22%20slang%3D%22en-US%22%3E%3CP%3EHere%20is%20the%20fix%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsupport.f5.com%2Fcsp%2Farticle%2FK02674159%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.f5.com%2Fcsp%2Farticle%2FK02674159%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECreate%20this%20key%20and%20your%20done.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1492355%22%20slang%3D%22en-US%22%3ERe%3A%20External%20private%20IP%20addresses%20registering%20with%20DNS%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1492355%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F667951%22%20target%3D%22_blank%22%3E%40Hohmaniacs1%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20specific%20to%26nbsp%3B%3CSPAN%3EBIG-IP%20Edge%20Clients%3F%26nbsp%3B%20The%20registry%20entry%20looks%20generic%2C%20just%20wanted%20to%20make%20sure.%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1495940%22%20slang%3D%22en-US%22%3ERe%3A%20External%20private%20IP%20addresses%20registering%20with%20DNS%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1495940%22%20slang%3D%22en-US%22%3E%3CP%3EGeneric%20reg%20key%2C%20not%20tied%20to%20F5.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F693319%22%20target%3D%22_blank%22%3E%40AwiegJax%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hello all,

 

I've been trying to fine-tune our NIDS configuration (which predates my employment here) and more specifically trying to figure out why certain IP addresses/ranges that we don't use, keep appearing in reports/logs.

 

I think I've figured out the root cause, but I'm not sure of the best way to fix it:

 

We have a number of remote users who connect to our network by VPN. As best I can tell, when their laptops connect to the network, they're sending updates to the DNS server running on the DC with both the IP address of their VPN interface (routable on our network) and their private IP address on their home LAN (obviously not routable) - if I do an nslookup on a domain machine, the DC returns two A records, one for each address.

 

This has a slight ripple effect through the network - which manifests mostly with Windows Update Delivery Optimization, where the peer discovery process frequently gets the non-routable private IP somehow and then tries to download Windows updates from it.

 

Long story short: what is the best way to prevent VPN'ed machines from registering external private IP addresses with the DNS server running on the DC?

8 Replies
Highlighted

We are experiencing the exact same issue, please respond if you found a resolution to this issue.

Highlighted
Highlighted

@Hohmaniacs1  Ditto!  I'm seeing their home LAN IP as well as their VPN IP.  This is totally strange.  I'm assuming it has something to do with our Firewall because when I connect in via Azure VPN instead of our default Firewall VPN no DNS record even shows up for my test device.... now I have 2 concerns.  Unable to reach an Azure connected client and having an unroutable LAN IP address in my DNS.  Weird. 

Highlighted

@AwiegJax 

I have a case open with Microsoft, will update when I hear anything. So far they have no clue.

Highlighted

@Hohmaniacs1 

 

Think I may have found the cause of our VPN Endpoints forwarding their VPN IP as well as their home LAN IP in our internal DNS.  There was a IP Helper set in our Fortigate Firewall that was set to "help" DNS pass though.  After disabling it then connecting to VPN from my test machine I'm now only seeing the routable VPN IP address and not the Endpoints Home LAN IP address. I tried removing the invalid DNS entries but they slowly show back up, it appears this setting may require an endpoint to disconnect and then reconnect in order to be applied.  

Dunno if that will help your situation but that appears to be what was causing our DNS issue.

 

Correction: This did not resolve our DNS issue for remote clients. I'm leaving that up as an idea for others but I did finally find out what is causing it.  If a user connects from home and is hardwaired and connected via WiFi, they then connect to VPN and the tunnel utlizes one adapter.  The adapter it isn't using is the IP address of the device that gets added to our DNS.  The Local LAN IP address of the adapter VPN is utilizing is NOT added to our DNS.  

I've still yet to find a solution to this other then disabling the WiFi adapters or disabling the "Register this connection's address in DNS".  

Highlighted

Here is the fix, https://support.f5.com/csp/article/K02674159

 

Create this key and your done.

Highlighted

@Hohmaniacs1 

Is this specific to BIG-IP Edge Clients?  The registry entry looks generic, just wanted to make sure.  

Highlighted

Generic reg key, not tied to F5. @AwiegJax