Configure DNS and WINS Servers for Mobile VPN with IPSec
- Assign or not assign the Network (global) DNS/WINS settings to mobile clients
- Assign DNS and WINS settings specified in the Mobile VPN with IPSec configuration to mobile clients
For more information about how DNS is used for lookups over a mobile VPN connection, go to DNS and Mobile VPNs.
DNS forwarding is not supported for mobile VPN clients.
In Fireware v12.2 or lower, Mobile VPN with IPSec clients automatically inherit DNS and WINS servers from the Network (global) DNS/WINS settings on your Firebox. Although you can specify up to three Network DNS servers, mobile VPN clients use only the first two in the list. For information about the Network DNS/WINS settings, go to Configure Network DNS and WINS Servers.
Use the Network DNS/WINS Settings
In the Mobile VPN with IPSec configuration, you can specify that mobile clients should use the Network (global) DNS/WINS settings on your Firebox.
When you select this option, mobile clients receive the DNS and WINS settings you specify at Network > Interfaces > DNS/WINS. For example, if you specify the DNS server 10.0.2.53 in the Network DNS/WINS settings, mobile VPN clients use 10.0.2.53 as a DNS server.
For mobile users to resolve internal domain names on your network, specify an internal DNS server first in the list. If you specify only a public DNS server, mobile users can resolve public domain names, but not internal domain names.
Although you can specify up to three Network DNS servers, mobile VPN clients use only the first two in the list.
For IPSec Mobile VPN clients, the domain name specified in the Network DNS settings on the Firebox is not used as a domain name suffix. You can specify a DNS domain name suffix in the VPN client. For more information, go to Configure DNS in the WatchGuard IPSec Mobile VPN client.
- Select Network > Interfaces.
The Interfaces configuration page appears.
- Select the DNS/WINS tab.
- In the DNS Server or WINS Server text boxes, type the primary and secondary address for each DNS or WINS server.
- Click Add.
- (Optional) Repeat Steps 3–4 to specify up to three DNS servers.
- Click Save.
- (Fireware v12.3 or higher) Select VPN > Mobile VPN.
- In the IPSec section, select Configure.
The Mobile VPN with IPSec page appears. - (Fireware v12.2.1 or lower) Select VPN > Mobile VPN with IPSec.
The Mobile VPN with IPSec page appears. - From the Groups list, select a group and click Edit.
The Mobile User VPN with IPSec Settings page appears. - Select the Advanced tab.
- In the DNS Settings section, select Assign the Network DNS/WINS Server settings to mobile clients.
- Click Save.
The Mobile VPN with IPSec page appears. - Click Save.
- Select Network > Configuration.
The Network Configuration dialog box appears. - Select the WINS/DNS tab.
The information on the WINS/DNS tab appears.
- In the DNS Servers text box, type the IPv4 or IPv6 address for each DNS server.
- Click Add.
- (Optional) Repeat Steps 3–4 to specify up to three DNS servers.
- In the WINS Servers text boxes, type the primary and secondary IPv4 address of the WINS servers.
- Click OK.
- Select VPN > Mobile VPN > IPSec.
The Mobile VPN with IPSec page appears. - From the Groups list, select a group and click Edit.
The Mobile User VPN with IPSec Settings page appears. - Select the Advanced tab.
- In the DNS Settings section, select Assign the Network DNS/WINS Server settings to mobile clients.
- Click OK.
The Mobile VPN with IPSec page appears. - Click OK.
Do Not Assign DNS or WINS Settings to Mobile VPN Clients
When you select the Do not assign DNS or WINS settings to mobile clients option, Mobile VPN with IPSec clients do not receive any DNS or WINS settings from the Firebox.
Use the DNS and WINS Settings in the Mobile VPN Configuration
You can specify that mobile clients should use the DNS and WINS settings in the Mobile VPN with IPSec configuration.
When you select the Assign these settings to mobile clients option, mobile clients use the domain name, DNS server, and WINS server settings you specify in the Mobile VPN with IPSec configuration. For example, if you specify example.com as the domain name and 10.0.2.53 as the DNS server, mobile clients use example.com for unqualified domain names and 10.0.2.53as the DNS server.
When you select this option, mobile clients do not use the servers specified in the Network DNS/WINS settings on the Firebox. For example, if you only specify a DNS server in the Mobile VPN with IPSec configuration, clients only receive that DNS server. If a WINS server and domain name are configured in the Network DNS settings, clients do not receive those settings.
You can specify one domain name, up to two DNS server IP addresses, and up to two WINS server IP addresses.
- (Fireware v12.3 or higher) Select VPN > Mobile VPN.
- In the IPSec section, select Configure.
The Mobile VPN with IPSec page appears. - (Fireware v12.2.1 or lower) Select VPN > Mobile VPN with IPSec.
The Mobile VPN with IPSec page appears. - From the Groups list, select a group and click Edit.
The Mobile User VPN with IPSec Settings page appears. - Select the Advanced tab.
- In the DNS Settings section, select Assign these settings to mobile clients.
- (Optional) In the Domain Name text box, type the domain name for your internal network.
- In the first DNS Servers text box, type the IP address of your primary DNS server.
- (Optional) In the second DNS Servers text box, type the IP address of your secondary DNS server.
- (Optional) In the first WINS Servers text box, type the IP address of your primary WINS server.
- (Optional) In the second WINS Servers text box, type the IP address of your secondary WINS server.
- Click Save.
The Mobile VPN with IPSec page appears. - Click Save.
- Select VPN > Mobile VPN > IPSec.
The Mobile VPN with IPSec page appears. - From the Groups list, select a group and click Edit.
The Edit Mobile User VPN with IPSec Settings page appears. - Select the Advanced tab.
- In the DNS Settings section, select Assign these settings to mobile clients.
- (Optional) In the Domain Name text box, type the domain name for your internal network.
- In the first DNS Servers text box, type the IP address of your primary DNS server.
- (Optional) In the second DNS Servers text box, type the IP address of your secondary DNS server.
- (Optional) In the first WINS Servers text box, type the IP address of your primary WINS server.
- (Optional) In the second WINS Servers text box, type the IP address of your secondary WINS server.
- Click OK.
The Edit Mobile VPN with IPSec page appears. - Click OK.