How to configure slave DNS server with Plesk behind NAT

Created:

2016-11-16 13:19:00 UTC

Modified:

2017-08-16 16:07:13 UTC

0

Was this article helpful?


Have more questions?

Submit a request

How to configure slave DNS server with Plesk behind NAT

Applicable to:

  • Plesk 12.5 for Linux
  • Plesk Onyx for Linux
  • Plesk 11.x for Linux
  • Plesk 12.0 for Linux

Symptoms

Master server with Plesk is running behind NAT.Slave DNS server is running outside of the internal network and has public IP.

Slave DNS server could not update any zones from Master server.

The following error is present in the /var/log/syslog file on the slave DNS server:

    named[4195]: transfer of 'domain.tld/IN' from <internal Master DNS ip>#53: failed to connect: host unreachable

Cause

Despite all DNS records are correct and pointed to the public IP, in the zones config, master server still has internal IP 10.10.10.10 . When master server sends request to update to the slave server, slave server tries to connect to the master server as per received zone config to the internal IP i.e. 10.10.10.10.

Since IP address 10.10.10.10 is unreachable from the slave's network it is failing with the mentioned error.

Resolution

Add two iptables rules to ensure all outgoing traffic redirection from internal 10.10.10.10 to public 79.79.79.79

    iptables -t nat -A OUTPUT -d 10.10.10.10 -p udp -j DNAT --to-destination 79.79.79.79
iptables -t nat -A OUTPUT -d 10.10.10.10 -p tcp -j DNAT --to-destination 79.79.79.79
Have more questions? Submit a request
Please sign in to leave a comment.