mirror of
https://github.com/netbirdio/docs.git
synced 2026-09-28 17:59:05 +02:00
docs: explain macOS DNS resolver behavior for match-only vs primary nameservers (#912)
* docs: explain macOS two-resolver-stack DNS behavior and the match-only vs primary nameserver split Lab-validated against client 0.76.3 (macOS 26, NetBird Cloud): - DNS troubleshooting: new Issue 5 'dig and host fail, but browsers and curl work (macOS)' with the scoped-resolver vs resolv.conf explanation, the language-runtime split table (pure-Go/dnspython/c-ares vs getaddrinfo), and the Windows nslookup-vs-NRPT analog; renumbered Issues 5-8 to 6-9; checklist step 6 now says why it prescribes dscacheutil/Resolve-DnsName - Internal DNS Servers: primary-vs-match now explains that match-only leaves resolv.conf untouched on macOS; new warning that emptying a match group's domains silently drops the search suffix (masked on domain-joined Windows); split-horizon example gains the route-everything-internal variant (the OpenVPN migration shape) - DNS overview: macOS line now distinguishes scoped resolvers from the primary case, where configd regenerates resolv.conf with NetBird's resolver * docs: add dashboard screenshot for the route-all-internal nameserver example * docs: polish wording in the macOS DNS additions * docs: promote the route-all-internal example to its own section * docs: drop the Example prefix from the nameserver scenario headings * docs: state the public-resolution prerequisite for an internal primary nameserver * docs: make the direct-resolver check precise * docs: anchor the scoped-resolver term to scutil output and split the dense solution paragraph
This commit is contained in:
@@ -98,7 +98,7 @@ Windows Firewall or endpoint security software can block NetBird traffic before
|
||||
|
||||
DNS on Windows has a few platform-specific failure modes worth checking separately:
|
||||
|
||||
- **Match-domain names don't resolve, even though the NRPT (Name Resolution Policy Table) rule was written.** A lingering Group Policy `DnsPolicyConfig` container can stop NetBird's rule from taking effect on an off-domain machine. See [DNS Troubleshooting: Issue 8 (lingering GPO)](/manage/dns/troubleshooting#issue-8-windows-nrpt-rule-is-written-but-never-takes-effect-lingering-gpo).
|
||||
- **Match-domain names don't resolve, even though the NRPT (Name Resolution Policy Table) rule was written.** A lingering Group Policy `DnsPolicyConfig` container can stop NetBird's rule from taking effect on an off-domain machine. See [DNS Troubleshooting: Issue 9 (lingering GPO)](/manage/dns/troubleshooting#issue-9-windows-nrpt-rule-is-written-but-never-takes-effect-lingering-gpo).
|
||||
- **Active Directory login, mapped drives, or DFS fail** while a file share by IP works. This is usually a DC-locator (`SRV` record) problem. See [Domain Controllers as routing peers](/manage/dns/internal-dns-servers#domain-controllers-as-routing-peers).
|
||||
- **NetBird won't start on a Domain Controller** and the peer shows disconnected. The Windows DNS Server service can claim WireGuard's UDP port 51820 before NetBird does, so the tunnel never comes up. See [WireGuard port conflict on Domain Controllers](/manage/dns/internal-dns-servers#wire-guard-port-conflict-on-domain-controllers).
|
||||
|
||||
|
||||
Reference in New Issue
Block a user