WSS: 'DNS_PROBE_FINISHED_NXDOMAIN' error when browsing to web sites

book

Article ID: 173590

calendar_today

Updated On:

Products

Web Security Service - WSS

Issue/Introduction

Users get a 'DNS_PROBE_FINISHED_NXDOMAIN' error message when they browse the Internet, however, the page does load if you try it several times.

This issue only happens when connected through the WSS Agent or Unified Agent.

This site can't be reached - DNS_PROBE_FINISHED_NXDOMAIN

Cause

One cause of this issue is recent versions of Windows prefer IPv6 over IPv4 when the "Block IPv6 traffic" option is enabled in the WSS portal.

If the computer prefers IPv6, DNS queries are first attempted with AAAA DNS requests.

If "Block IPv6 traffic" is enabled in the portal, IPv6 DNS queries are blocked resulting in the error.

Resolution

There are a few potential solutions to this issue. And it may require a combination of these to fully resolve the issue.

  • Update network drivers.

  • Prefer IPv4 over IPv6 on the client computer.

  • Disable IPv6 on the client computer. (Not recommended by Microsoft)
  • Uncheck the "Allow IPv6 traffic" option under Connectivity > WSS Agent in the WSS portal.

Attachments