Skip to main content
nverma
Staff
Staff
May 17, 2022

Technical Tip: Custom DNS servers are not supported with L2TP tunnels

  • May 17, 2022
  • 0 replies
  • 2942 views
Description This article describes how custom DNS servers are not supported with L2TP tunnels.
Scope FortiGate.
Solution

Custom DNS servers are not supported with L2TP tunnels. Users connected via L2TP will always retrieve FortiGate system DNS servers.


To change the configured DNS servers in GUI, Network -> DNS, then set the primary and secondary DNS servers.

 

With the CLI:

 

config system dns

    set primary x.x.x.x

    set secondary y.y.y.y
end

 

Changing the system DNS is a global change and does not affect only L2TP. The FortiGate will now use the configured DNS servers for DNS queries.

 

It is possible to configure custom DNS servers on the L2TP adapter in Windows by editing the Internet Protocol Version 4 (TCP/IPv4) settings.

 

Example:

 

control-panel-L2TP.jpg

 

When the L2TP VPN is connected, use ipconfig /all in Command Prompt or PowerShell to verify the custom DNS servers are configured.

 

L2TP-custom-DNS.jpg

 

Related articles:

Technical Tip: How to configure L2TP using interface/route based IPsec VPN

Technical Tip: Resolving Internet Connectivity Issues with L2TP IPsec VPN Using Windows Native Client

Troubleshooting Tip: L2TP in IPsec connectivity issues

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!