Project

General

Profile

Actions

Feature #16615

closed
MM MM

Omit NAT64 address for queries from the firewall itself

Feature #16615: Omit NAT64 address for queries from the firewall itself

Added by Marcos M 9 months ago. Updated 6 months ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
DNS Resolver
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.03
Release Notes:
Default

Description

Using DNS64 can result in the firewall itself trying to connect to a NAT64 address. For example:

[26.03-DEVELOPMENT][admin@gw]/root: ping6 github.com
PING(56=40+8+8 bytes) 2806:db8::1 --> 64:ff9b::8c52:7203

Doing NAT64 is not useful in this case since the firewall would already have an IPv4 address to reach the IPv4-only host. However the firewall should still be allowed to connect to NAT64 addresses if another device is set up to do the NAT64 translation instead. Automatic unbound configuration should be generated when appropriate to omit NAT64 addresses for DNS queries from the firewall itself.


Related issues 1 (0 open1 closed)

Related to Feature #16534: Omit reserved NAT64 addresses from DNS64 answersResolvedMarcos M

Actions

MM Updated by Marcos M 9 months ago Actions #1

  • Related to Feature #16534: Omit reserved NAT64 addresses from DNS64 answers added

MM Updated by Marcos M 9 months ago Actions #2

  • Status changed from New to Feedback
  • % Done changed from 0 to 100

Applied in changeset commit:b795f53a87bb005168a4e3ef5a58a199234ed170.

JP Updated by Jim Pingle 6 months ago Actions #3

  • Status changed from Feedback to Resolved

Behavior looks as expected from both the client and localhost with either option state.

Actions

Also available in: Atom