[Dnsmasq-discuss] Responding to remote DNS queries
Donald Muller
donmuller22 at outlook.com
Fri Sep 25 19:16:16 UTC 2026
I heard back from Synology. The issue is on the Synology side.
In their ticket response -
This issue is likely related to how Site-to-Site VPN routing functions on Synology routers. In SRM, Site-to-Site VPN tunnels are designed to route traffic between client devices across the two local subnets (LAN-to-LAN). KB documentation confirms that traffic generated directly by the router itself—specifically the Network Tools ping service—is routed via the router's WAN interface rather than through the VPN tunnel. For other router-originated traffic, such as DNS forwarding from the DNS Server package, the routing behavior depends on how traffic is directed; it is possible that the DNS Server package's outbound queries to the remote forwarders are not being routed through the VPN tunnel to the remote private subnet.
If I set up devices on site B to use dnsmasq on Site A it works fine. So dnsmasq is configured and working properly. However, I do not want to send all DNS queries from Site B to Site A.
I responded to their initial response basically saying it is a poor design and that their DNS package should respect the rules set it place. They agreed and this was their response.
Thank you for your detailed feedback. I completely understand your expectation — the Forwarding Zones should work as configured, and I agree that having SRM packages respect the routing setup is a reasonable requirement.
Our engineering team is currently investigating the specific behavior of the DNS Server package in conjunction with Site-to-Site VPN to confirm the exact cause and available options for your use case. As we are observing a public holiday this week, I will follow up with a concrete answer early next week once our team has completed their review.
I appreciate your patience and will be in touch as soon as possible.
Posting this in case anyone else runs into this issue with Synology SRM.
Don
________________________________
From: Dnsmasq-discuss <dnsmasq-discuss-bounces at lists.thekelleys.org.uk> on behalf of Donald Muller <donmuller22 at outlook.com>
Sent: Thursday, September 24, 2026 3:12 PM
To: dnsmasq-discuss <dnsmasq-discuss at lists.thekelleys.org.uk>
Subject: [Dnsmasq-discuss] Responding to remote DNS queries
Hi,
I have site-to-site connectivity set up between two sites using Synology RT6600ax routers. It works great.
Site A runs dnsmasq on a NAS server for local DHCP and local DNS resolution and forwarding. I have names defined in dnmasq for Site A and Site B. When I ping by name devices in Site A or Site B resolution works fine. They are .sitea.home.arpa and .siteb.home.arpa.
Site B runs the Synology SRM DNS package. I have two forwarding zones set up to on the SRM DNS package to send requests for sitea.home.arpa and siteb.home.arpa to the dnsmasq server at sitea. When I ping these names resolution fails. Anything special I need to do in the dnsmasq configuration to accept and reply to DNS query requests from a remote network? Is there a way to log queries and responses from the Site B network to see if they are coming in? I have the following in my dnsmasq configuration file.
log-queries=extra
log-queries
#local-service
#localise-queries
This creates a very large log file. Is there a way to just log queries from Site B? If a query came in from Site B and dnsmasq wasn't properly configured to respond to it would it log this?
I have also opened a ticker with Synology to see if I have everything set up properly on the routers.
Thanks
Don
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/attachments/20260925/483b5638/attachment.htm>
More information about the Dnsmasq-discuss
mailing list