Technical Tip: Configuring Secure DDNS for FortiSASE Connected Clients
| Description | This article describes the issue where FortiSASE-connected clients experience secure DDNS updates being refused by the DNS server, which prevents clients from registering their DNS names. It explains the root cause of the problem and provides a detailed, step-by-step solution to resolve the issue. |
| Scope | FortiSASE, FortiGate. |
| Solution | In Secure DDNS operations, the process is as follows:
FortiSASE applies SNAT to UDP DNS requests coming from FortiClient (using the FortiSASE tunnel IP), but it cannot apply SNAT to TCP DNS requests. As a result, the DNS server notices a mismatch in the source IP between Step 4 (TCP DNS) and Step 5 (UDP DNS – authenticated update) and refuses the update.
To resolve the issue, follow these steps:
Related document: |
