Technical Tip: Configuring split-dns on FortiGate for split-tunnel IPsec Dialup VPN
| Description | This article describes how to configure split-dns for a split-tunnel IPsec dialup vpn with FortiClient on FortiGate to resolve an internal domain. |
| Scope | FortiGate v7.2, v7.4, v7.6. |
| Solution | Topology: client –internet-- FGT-kenobi –ipsec-- FGT-A -> server (Internal Domain, win.server.fgt resolves to 10.191.1.231)
This dialup IPsec configuration is an ikev2 split-tunnel:
Note: FQDNs are not supported in split-tunnel destinations. If FQDNs have been configured in the split-tunnel address group, it cannot be applied in the (set ipv4-split-include) config of the dialup IPsec.
After these steps, FortiGate and the VPN client should be able to ping the internal domain:
|







