Last Modified: Jan 29, 2019
See more info
Known Affected Versions:
12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 188.8.131.52, 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 12.1.4, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52, 184.108.40.206, 220.127.116.11, 13.1.1, 18.104.22.168, 22.214.171.124, 126.96.36.199, 188.8.131.52
Opened: Aug 11, 2016
Related AskF5 Article: K13222132
DNS resolution does not work in a particular case of DNS Relay Proxy Service, when two adapters have the same DNS Server address on Microsoft Windows version 10.
DNS resolution completely stops working on client systems until the VPN is disconnected.
This issue occurs when all of the following conditions are met: -- Your BIG-IP APM configuration uses a network access profile. -- The user device is running Windows 10 and is connected to two networks through two network interfaces. -- The Windows user has installed the BIG-IP Edge Client that includes the DNS Relay Proxy Service. -- Prior to establishing an access session, the lower index network interface of the Windows device is disconnected. -- The Windows user establishes an access session using BIG-IP Edge Client. -- The Windows device's lower index network interface is reconnected. -- The Windows user attempts a DNS resolution.
To work around this issue, add the following registry key: HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient with DWORD EnableMultiHomedRouteConflicts set to 0. This reverts the Windows DNS client behavior to pre-Windows 10 behavior, so the DNS relay proxy creates listeners on loopback for incoming requests, and the driver redirects DNS requests to the listener on the loopback. Important: Use extreme care when editing Windows registry keys. Incorrect modification of keys might cause unexpected behavior. For step-by-step instructions for adding this registry key, see K13222132: The DNS Relay Proxy Service may fail to resolve DNS requests :: https://support.f5.com/csp/article/K13222132.