Skip to main content
khannas
Staff
Staff
December 27, 2023

Troubleshooting Tip: Issues with resolving the internal FQDN when IPv6 is enabled on the Endpoint NIC

  • December 27, 2023
  • 0 replies
  • 10736 views
Description This article describes how to troubleshoot issues with resolving the internal FQDN when IPv6 is enabled on the Endpoint NIC.
Scope All Windows versions of FortiClient.
Solution

When IPv6 is enabled, A and AAAA DNS requests are sent simultaneously.

  1. If the AAAA returns 'No such name' first, it means that the DNS request considers this domain to have no IP and the issue will be experienced.
  2. If A returns first with a valid IPv4 address, there is no issue.

 

When IPv6 is disabled, only an A request will be sent and receive a valid IPv4, meaning no issue will be observed.

 

To resolve this issue, take one of the following actions:

 

Disable ParallelAandAAA capability:

  1. In Registry Editor, go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters.
  2. Set 'DisableParallelAandAAAA'=dword:00000001.

Enable SMHNR:

  1. In Local Group Policy Editor, go to Computer Configuration -> Administrative Templates -> Network -> DNS Client -> Turn off smart multi-homed name resolution.
  2. Select policy setting.
  3. Set it to Disabled, then select OK.
  4. In Registry Editor, go to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient.
  5. Set 'DisableSmartNameResolution'=dword:00000000.

If issues still persist, contact Fortinet Support.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.