Skip to main content
mle2802
Staff
Staff
October 14, 2025

Troubleshooting tip: Internal DNS queries are not resolved when FortiGate is used as a DNS server

  • October 14, 2025
  • 0 replies
  • 1634 views
Description This article describes how to troubleshoot issue with resolving internal DNS queries.
Scope FortiGate.
Solution

Follow the steps in this document to configure FortiGate as a DNS server FortiGate DNS server | FortiGate / FortiOS 7.6.4 | Fortinet Document Library.

To configure a DNS server, go to Network -> DNS Servers. If the option is not visible, go to System -> Feature Visibility and enable DNS Database in the Additional Features section.


Screenshot 2025-10-11 102720.png
From the CLI:

config system dns-server

    edit "port2"

    next

end

Verify that the DNS entry is properly configured on FortiGate to resolve internal DNS queries. To do so, go to Network -> DNS Servers and double-click on the DNS database.

Screenshot 2025-10-11 103539.png


From the CLI:

config system dns-database
    edit "TAC"
        set domain "tac.local"
            config dns-entry
                edit 1

                    set hostname "test"

                    set ip 192.168.100.1

                next

            end

        next

    end


From the client side, DNS is resolved for public DNS queries but not internal ones.

Screenshot 2025-10-11 105352.png
This happens due to the DNS zone being set to 'public' instead of 'shadow'. Refer to this document for more information regarding the different view types in a DNS zone: Technical Tip: DNS Database view type Shadow and Public for explicit proxy.

To verify the view type, go to Network -> DNS Servers and double-click on the DNS database.

Screenshot 2025-10-11 110553.png
Switch the view type to 'shadow' and confirm internal DNS queries are resolvable.

Screenshot 2025-10-11 111014.png
Screenshot 2025-10-11 111226.png

 

Related articles:
Technical Tip: FortiGate Troubleshooting DNS commands

Technical Tip: DNS server on FortiGate caused FortiGate DNS latency

Technical Tip: DNS troubleshooting

Technical Tip: DNS stops working when using custom DNS

Technical Tip: FortiGate DNS Server works as DNS proxy

Technical Tip: DNS server is unreachable when using custom DNS 
Technical Tip: DNS over TLS (DoT) with 3rd Party Global DNS (Google DNS)

Technical Tip: Enable DNS over TLS with Google DNS servers
Technical Tip: Different options of configuring DNS server on FortiGate

Troubleshooting Tip: Using Cloudflare DNS with DNS over TLS showing as unreachable 

Troubleshooting Tip: Google DNS with DNS over TLS showing as unreachable

Troubleshooting Tip: Domain Name ServDNS not responding

Troubleshooting Tip: Quad9 DNS with DNS over TLS showing as unreachable

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!