Skip to main content
ChrisTan
Staff
Staff
March 26, 2026

Technical Tip: Difference between FortiSASE custom DNS settings in public mode and private mode.

  • March 26, 2026
  • 0 replies
  • 94 views
Description This article describes the difference between public and private mode in FortiSASE DNS settings.
Scope FortiSASE.
Solution

In FortiSASE, there are two kinds of custom DNS settings:

 

2026-03-23_15h58_14.png

 

Address type Description
Public address The backend PoP will send the DNS enquiry from the WAN port.
Private address For local DNS, where the DNS servers are on-prem through the SPA tunnel. 

 

In the private address type, the PoP will force the DNS enquiry over the SDWAN interfaces and use the source IP as loopback if the tunnel uses BGP on loopback. In this case, the DNS will fail if it is set to public.

 

Additionally, make sure the DNS server supports TLS(TCP/853) if select TLS(TCP/853) in the DNS protocols.