SD-WAN

 View Only
Expand all | Collapse all

SDWAN Orchestrator and Edgeconnects

This thread has been viewed 71 times
  • 1.  SDWAN Orchestrator and Edgeconnects

    Posted Sep 01, 2025 11:36 AM

    Hello,

    We have a weird issue.

    We are using ACLs for forwarding the traffic to a specific BIO, the ACL is using destination : domain and specific FQDNs, but it's not working.

    After checking the traffic flows, we can see the destination is not an FQDNs but the resolved IP instead of. Hence that's why the ACL is not working as the condition is the destination FQDNs.

    Why the Edgeconnects are not showing the FQDNs and use the IP for destinations ?



    -------------------------------------------


  • 2.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 02, 2025 06:43 AM

    The flow details will always show IP addresses for IP1 and IP2, so that is expected.

    For first packet classification, the EC would need to snoop DNS. Is the DNS server request and response also passing through the appliance? If not, your symptoms are expected. If you can get the DNS flows to route through the appliance, I would expect it to be able to place the flow into the correct overlay from first packet and show the 'First Packet Dst Domain' in flow details under the AVC/DNS tab, example below:

    -------------------------------------------



  • 3.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 05, 2025 04:47 AM
    Edited by Clem58 Sep 05, 2025 04:47 AM

    Sorry I don't really get your message, here is what I get for the destinations which I have issues:

    In the flows, I can see a lot of FQDNs in IP2

    Example :

    -------------------------------------------



  • 4.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 05, 2025 05:12 AM

    Interesting that the src domain was DNS snooped successfully, but not the destination.

    Which version of ECOS are you running?

    -------------------------------------------



  • 5.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 05, 2025 05:16 AM

    ECOS version:  9.3.7.0_96892

    -------------------------------------------



  • 6.  RE: SDWAN Orchestrator and Edgeconnects
    Best Answer

    Posted Sep 05, 2025 05:27 AM
    Edited by Clem58 Sep 05, 2025 08:57 AM

    Thanks. First, a little disclaimer: without having done any analysis other than the brief discussion here, the suggestions that follow are made without any warranty of success and you may wish to open a case with our TAC team for full analysis.

    That said, you may be running into a defect, possibly VXOA-81111 which was resolved from ECOS 9.4.4.2 and 9.4.5.0 onwards.

    It could be worthwhile upgrading one of your affected EC appliances to the latest GA version (currently 9.4.4.2) as a test. 
    Please read the release notes before upgrading.

    Otherwise, please do consider opening a TAC case for investigations.

    -------------------------------------------



  • 7.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 05, 2025 05:27 AM

    Something I just tested, with some other Edgeconnects, on ECOS 9.4.3.5_99663, the IP2 is correctly showing the FQDNs, so I wonder is it's not an issue with the OS indeed.

    -------------------------------------------



  • 8.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 05, 2025 05:30 AM

    There is another DNS related fix (77502) present from 9.4.3.3 so you may have confirmed an upgrade will help in your test. Sounds positive!

    -------------------------------------------



  • 9.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 05, 2025 05:38 AM

    Ok I think the OS could be the root source of the issue indeed !

    Many thanks CG for your help and quick response !

    -------------------------------------------



  • 10.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 05, 2025 05:42 AM

    It's a pleasure :)

    -------------------------------------------



  • 11.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 05, 2025 05:45 AM

    had the same issue. if you run show dns cache on any version of 9.4.3.x your be met with the following output

    % An internal error occurred. 

    Only fix will be 9.4.4.2 + as was confirmed to me by Aruba there will be no 9.4.3.8

    -------------------------------------------



  • 12.  RE: SDWAN Orchestrator and Edgeconnects

    Posted Sep 05, 2025 05:55 AM

    Hi Matthew,

    Interestingly I have this "% An internal error occurred" output on the ECs with ECOS 9.4.3.5_99663 but which I don't have the FQDNs issue, and I don't have the output bug on the one with ECOS 9.3.7.0_96892 but which has the FQDNs issue.

    -------------------------------------------



  • 13.  RE: SDWAN Orchestrator and Edgeconnects

    Posted 30 days ago

    Hello,

    Our partner has updated the Edgeconnects to the 9.4.3.5_99663 version, it worked during a while, doing the resolutions correctly.

    But recently it's again doing the same issue, not resolving the IPs to FQDNs for certain destinations, and then our ACL is not working, as it's filtering to domains.

    -------------------------------------------



  • 14.  RE: SDWAN Orchestrator and Edgeconnects

    Posted 30 days ago

    Ah maybe you need to move to 9.4.4.2 or 9.4.5 onwards after all. 

    -------------------------------------------



  • 15.  RE: SDWAN Orchestrator and Edgeconnects

    Posted 30 days ago
    Edited by Clem58 30 days ago

    I've found the problem, this ECs is a hub and has a default 0.0.0.0/0 route to the core switch of the site, the DNS resolution was set with "any" interface, so when it was using the LAN interface the resolution was "redirected"

    If I ping from the CLI without indicated interface I can see it's using management interface.

    So I defined the DNS resolution using mgmt0 interface and now no more DNS resolution issue in the flows.

    It was working with the other ECs because they are spokes without local default route and using loopback for DNS resolution.

    Also I think it's also related with the fact I can ping 8.8.8.8 from the LAN interface source IP, but not with the source interface itself, are you aware of this behavior ?

    -------------------------------------------



  • 16.  RE: SDWAN Orchestrator and Edgeconnects

    Posted 30 days ago

    Excellent work, thanks for sharing the solution!

    -------------------------------------------