How to resolve Private DNS Zone names while using Point to Site VPN

Sam Yande 1 Reputation point
2022-07-22T15:26:45.297+00:00

I understand P2S VPN doesnt resolve private dns zone names by default but we need to resolve them as there is no corporate network or private dns server.

I heard the VPN client XML profile can include DNS zone configuration. Can you share a sample XML with such DNS config?

Azure DNS
Azure DNS
An Azure service that enables hosting Domain Name System (DNS) domains in Azure.
629 questions
Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,436 questions
Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
484 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Alan Kinane 16,806 Reputation points MVP
    2022-07-22T16:06:23.82+00:00

    Here's how to configure the DNS servers in the config file.

    https://video2.skills-academy.com/en-us/azure/vpn-gateway/openvpn-azure-ad-client#how-do-i-add-custom-dns-servers-to-the-vpn-client

    Up to recently I believe you had to configure a DNS forwarder (VM in Azure acting as a DNS server) that is like to the private DNS zone. Azure DNS Server IP address is: 168.63.129.16

    However, there is a new server (currently still in public preview) which may give you another option.

    Have a look at Azure DNS private resolver - https://video2.skills-academy.com/en-us/azure/dns/dns-private-resolver-overview


  2. Raffaele Fanizzi 0 Reputation points Microsoft Employee
    2023-09-18T15:20:31.53+00:00

    Please, double check your XML. <dnsssuffix> nodes are wrong. Is dnssuffix and not dnsssuffix

    Try the followings:

    <dnssuffix>.azurecr.io</dnssuffix>
    <dnssuffix>.azuredatabricks.net</dnssuffix>
    <dnssuffix>.azurestaticapps.net</dnssuffix>
    <dnssuffix>.1.azurestaticapps.net</dnssuffix>
    <dnssuffix>.2.azurestaticapps.net</dnssuffix>
    <dnssuffix>.azurewebsites.net</dnssuffix>
    <dnssuffix>.scm.azurewebsites.net</dnssuffix>
    <dnssuffix>.blob.core.windows.net</dnssuffix>
    <dnssuffix>.database.windows.net</dnssuffix>
    <dnssuffix>.datafactory.azure.net</dnssuffix>
    <dnssuffix>.dfs.core.windows.net</dnssuffix>
    <dnssuffix>.file.core.windows.net</dnssuffix>
    <dnssuffix>.postgres.database.azure.com</dnssuffix>
    <dnssuffix>.cognitiveservices.azure.com</dnssuffix>
    <dnssuffix>.vault.azure.net</dnssuffix>
    <dnssuffix>.vaultcore.azure.net</dnssuffix>
    <dnssuffix>.wvd.microsoft.com</dnssuffix>
    <dnssuffix>.azurecontainerapps.io</dnssuffix>
    <dnssuffix>.notebooks.azure.net</dnssuffix>
    <dnssuffix>.api.azureml.ms</dnssuffix>