Dns Resolver Features; Typical Dns Resolver Application - Vpn Failover - Avaya G250 Administration Manual

Media gateways
Hide thumbs Also See for G250:
Table of Contents

Advertisement

The DNS resolver feature is intended to provide a backup mechanism for VPN hubs using DNS.
For more information about VPNs on the G250 and G350, see
page
549.

DNS resolver features

The G250/G350 supports the following DNS resolver features:
Fully compliant with RFC1034, RFC1035, and RFC1123
Maintains a global DNS database for all interfaces. The database is compiled using:
Static (user-defined) DNS servers
Automatically-learned DNS servers. DNS servers can be automatically learned by the
FastEthernet 10/2 interface when it is configured as a DHCP client or configured for
PPP. For more information on DHCP Client, see
page 218.
Note:
The following PPP interfaces can be configured to automatically learn the DNS
Note:
servers in the system:
- FastEthernet with PPPoE
- Dialer interface
- Serial interface
The most common application of this configuration is for connecting the G250/G350 to
the Internet and getting the DNS server information from the ISP. Therefore, interfaces
configured to automatically learn the DNS servers in the system are usually the
FastEthernet with PPPoE interface and the Dialer interface.
Typical DNS resolver application – VPN failover
In this typical application, the DNS resolver feature is used to provide a VPN failover
mechanism between two main offices. The failover mechanism is implemented as follows.
The VPN branch office(s) connect to two main offices (the VPN remote peers) that are
configured with the same FQDN name, but have different IP addresses. When a branch office
makes a DNS query to resolve the VPN remote peer name to an IP address, it receives a list
with the IP addresses of both main offices, selects the first one, and builds a VPN tunnel with it.
If the first main office fails, the branch office sends another DNS query, and receives the IP
address of the second main office in reply. It will then start a VPN tunnel with the second main
office.
This typical application is described in full in
Configuring IPSec VPN on
Configuring DHCP client
Failover using DNS
on page 613.
DNS resolver
on
Issue 5 June 2008
99

Advertisement

Table of Contents
loading

This manual is also suitable for:

G350

Table of Contents