FAQ for private access security
Find answers to common questions about SASE private access security, including DNS configuration, connectivity troubleshooting, and connector setup.
Configuring internal DNS for domain-based services
-
If your network uses PrivateZone, SASE automatically synchronizes resolution data from PrivateZone. No additional configuration is required on the SASE console.
-
If your network does not use PrivateZone, configure a custom DNS service. You can specify multiple server IP addresses. If DNS resolution fails on one server, the request is forwarded to the other servers.
For more information about SASE domain resolution policies and how to configure a custom DNS service, see Application domain name resolution.
Application inaccessible despite successful pings
The ping utility is not reliable for determining connectivity. On macOS, pings are allowed across all subnets. On Windows, pings are allowed only to the 198.18 and 198.19 subnets.
Use telnet, nc (netcat), or other similar commands to verify connectivity.
Windows devices unable to access internal domain services
This issue typically occurs on Windows 11. Browsers on Windows 11 often have a secure DNS setting that must be disabled to allow access. If DNS-over-HTTPS (DoH) was enabled on a Windows 11 system, either by security software or manually, switch it to a non-encrypted mode.
Troubleshooting private access failures
On the Log Audit page, find the relevant access log and check whether the traffic was allowed or blocked.
-
If the action is
block, check the reason. Common causes include an unconfigured application, unassigned access permissions, or a non-compliant terminal security baseline. Adjust the configuration based on the reason provided. -
If the action is
allow, go to the page and verify that the network where the application resides is connected.If the application is deployed on Alibaba Cloud, verify that the corresponding VPC or CEN is connected.
If the application is deployed in a non-Alibaba Cloud environment, verify that the dedicated line is connected and that the SASE connector is associated with the application.
Downloading the connector
Go to the Connector Management page, copy the command, and run it. For detailed instructions, see Enable network access for non-Alibaba Cloud services.