DNS Resolution Issues across Hubs

Greg Bonk 41 Reputation points
2024-01-16T16:56:27.74+00:00

I have an existing VWAN and single VHUb. The Existing setup. All that is shown here in Subscription A works great. The sub A hub does not have a Firewall at this time. The VNets that are peered with the existing Hub, all have their Vnet DNS set to 10.2.0.4 which is the lP of the Private DNS Resolver. The VNet of the Private DNS Resolver has our Private DNS zones linked and doesn't have any issues resolving private DNS.

Now I am creating a second subscription with a new hub. The second subscription is to track costs for this new infrastructure. The new Hub (B) is attached to the existing VWAN.
The new B Hub does have a Firewall attached. The firewall is a standard firewall, and has a policy with the DNS Proxy Enabled. The DNS proxy IP points to the Private DNS resolver peered with HUB A. User's image

The Vnet that is in Sub B and is peered with Hub B has its DNS pointing to the Firewall attached to the HUB B. User's image

The VM that is in Sub B is accessible via its private IP. I can run nslookup and resolve IPs if I add the server IP of the Private DNS Resolver.

Works Great using the IP of the Private DNS Resolver User's image

The problem is when I'm using the FIREWALL as the DNS Proxy. User's image

Some of the Firewall Logs...

User's image

There are time outs in the firewall logs when it tries to forward DNS queries to the DNS private resolver I know the two hubs are properly swapping and auto discovering routes. The VM can directly query the private resolver in the other hub, and I can connect to the VM from the other hub. I know the default route tables are working... And that's where I think this is failing. Looking at the default route table the CIDR of the Hub's B Network or IP of the Firewall is not automatically propagated via the hub which I think is causing my failure ? What are my options on resolving this ? Simple network diagram

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
197 questions
Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
598 questions
Azure
Azure
A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.
1,055 questions
{count} votes