Have a hub and spoke VPN setup with DNS on hub network. Spoke network
domain devices are provisioned by DHCP with our DNS. Any domain joined
device can resolve DNS without issue. I have some android devices on the
spoke side which will not resolve. T...
The DNS servers are my local domain DNS on my hub network. I have tested
the same devices with this DNS configuration without the IPSEC VPN and
they work.
Replying to all your questionsAndroid Devices ping the DNS server? Yes
by IPAre they assigned a different subnet on the firewall than the
domain joined devices? No same subnetAre you using Identity based rules
that the Android devices wouldn't match?...