After continuing to work with Zywall support it was determined that this issue was caused by the large port forwarding range that had been setup for our VOIP phone system
Main Topics
Browse All TopicsWe have a Zyxel Zywall 35 on the UTM 4.0.4(WZ.6) firmware - it exhibited the same behaviour on the 4.0.2(WZ.2) firmware - that is blocking DNS lookups. The dns servers are properly configured under the DNS section, on both the main tab and the DHCP tab, and we have all logging enabled but are unable to identify any apparent culprit in the logs. This firewall is intended to replace an existing pfsense firewall, and has been configured to mirror the pfsense's settings. We can swap the pfsense box in and everything works fine, but when we switch to the Zywall, we lose dns lookups from our workstations and our DNS servers. We still have internet connectivity and are able to ping, browse and connect via ip address, but are unable to resolve names. Any suggestions are appreciated.
Thanks,
Matt
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: dpk_walPosted on 2009-11-01 at 04:46:24ID: 25713534
Are you using Zywall IP as DNS server; many firewalls cannot act as DNS Server itself; but can forward DNS requests; can you try specifying DNS server as given by ISP to be included in your DHCP scope [if applicable] and check results.
Use nslookup website dns-server-ip from CLI to check results.
Please check and update.
Thank you.