Skip to main content
chrispaesano
New Member
July 16, 2015
Solved

Pinging by name with iOS Dialup VPN

  • July 16, 2015
  • 3 replies
  • 3696 views

I have an iOS Dialup VPN set up. I can connect to the VPN and ping/rdp to any host on the network if I use an IP but DNS doesn't work.

 

I've configured the network's local DNS server in the settings but this didn't work. I can't ping by name, I also can't ping by FQDN. Any ideas?

    Best answer by TheJaeene

    @chris

     

     

    The DNS can be set on a per Tunnel Basis.

     

    Some iOS Devices seem to have problems resloving .local domains.

     

     

    Check out this CLI example:

     

    edit "tu-dialup" set type dynamic set interface "wan2" set keylife 28800 set mode aggressive set peertype one [style="background-color: #ffff00;"]set mode-cfg enable[/style] [style="background-color: #ffff00;"]set ipv4-dns-server1 10.10.10.1[/style] [style="background-color: #ffff00;"] set ipv4-dns-server2 10.10.10.254[/style] set proposal 3des-sha1 aes128-sha1 set negotiate-timeout 15 set dhgrp 2 set xauthtype auto set authusrgrp "vpn" set peerid "remote" set ipv4-start-ip 10.10.100.1 set ipv4-end-ip 10.10.100.10 set ipv4-netmask 255.255.255.128 [style="background-color: #ffff00;"]set domain "my.domain"[/style]

     

    [style="background-color: #ffff00;"] [/style]

     

    3 replies

    gschmitt
    New Member
    July 17, 2015

    Can you ping the DNS server with the device in question?

     

    What services did you allow? Just PING (ICMP) and RDP?

     

    Basically you should make sure the device can actually reach the DNS server on TCP/UDP 53 (DNS)

    TheJaeene
    TheJaeeneAnswer
    New Member
    July 17, 2015

    @chris

     

     

    The DNS can be set on a per Tunnel Basis.

     

    Some iOS Devices seem to have problems resloving .local domains.

     

     

    Check out this CLI example:

     

    edit "tu-dialup" set type dynamic set interface "wan2" set keylife 28800 set mode aggressive set peertype one [style="background-color: #ffff00;"]set mode-cfg enable[/style] [style="background-color: #ffff00;"]set ipv4-dns-server1 10.10.10.1[/style] [style="background-color: #ffff00;"] set ipv4-dns-server2 10.10.10.254[/style] set proposal 3des-sha1 aes128-sha1 set negotiate-timeout 15 set dhgrp 2 set xauthtype auto set authusrgrp "vpn" set peerid "remote" set ipv4-start-ip 10.10.100.1 set ipv4-end-ip 10.10.100.10 set ipv4-netmask 255.255.255.128 [style="background-color: #ffff00;"]set domain "my.domain"[/style]

     

    [style="background-color: #ffff00;"] [/style]

     

    chrispaesano
    New Member
    July 21, 2015

     

    Thank you! The domain name is what solved this. Instant success after adding the local domain. That option isn't available in the GUI. Much appreciated!

     

     

    jkassner wrote:

    @chris

     

     

    The DNS can be set on a per Tunnel Basis.

     

    Some iOS Devices seem to have problems resloving .local domains.

     

     

    Check out this CLI example:

     

    edit "tu-dialup" set type dynamic set interface "wan2" set keylife 28800 set mode aggressive set peertype one [style="background-color: #ffff00;"]set mode-cfg enable[/style] [style="background-color: #ffff00;"]set ipv4-dns-server1 10.10.10.1[/style] [style="background-color: #ffff00;"] set ipv4-dns-server2 10.10.10.254[/style] set proposal 3des-sha1 aes128-sha1 set negotiate-timeout 15 set dhgrp 2 set xauthtype auto set authusrgrp "vpn" set peerid "remote" set ipv4-start-ip 10.10.100.1 set ipv4-end-ip 10.10.100.10 set ipv4-netmask 255.255.255.128 [style="background-color: #ffff00;"]set domain "my.domain"[/style]

     

    [style="background-color: #ffff00;"] [/style]

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!