Skip to main content
larsbollas
Staff
Staff
September 6, 2022

Technical tip: DNS over TLS using Cloudflare DNS

  • September 6, 2022
  • 0 replies
  • 8946 views
Description

This article describes how to configure FortiGate DNS over TLS using Cloudflare DNS.


Cloudflare DNS:

Primary DNS 1.1.1.2

Secondary DNS 1.0.0.1

Scope

From GUI:

 

larsbollas_0-1662443742639.png

 

From CLI:

# config system dns
    set primary 1.1.1.2
    set secondary 1.0.0.1
    set protocol dot
    set server-hostname "1dot1dot1dot1.cloudflare-dns.com"
end

Note.

Using incorrect server hostname will result to DNS failure.

Solution When configuring from GUI, do not forget to change the default server hostname 'globalsdns.fortinet.net'.

When using Cloudflare DNS, use 'one.one.one.one' or '1dot1dot1dot1.cloudflare-dns.com' as the server hostname.

 

Related article:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-DNS-over-TLS-configuration/ta-p/193830

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.