Skip to main content
Steffen
New Member
October 14, 2021
Question

Best practises DNS over IPSEC with Fall Back to public DNS

  • October 14, 2021
  • 2 replies
  • 3088 views

Hello all,

 

we have a Fortigate F61 and this firewall is planned for a small business location with 10 users. The DNS servers are located in the headquarters and the small site is connected to the main site via IPSec. Is there a best practice way to have DNS over Ipsec and still have the internet working in the event of a failure?

 

Many thanks for the help!

    2 replies

    emnoc
    New Member
    October 14, 2021

    Yeah run a local dns-server if 100% business connectivity is require. if you run it over ipsec and do not have any redundancy you would be jacked to say the least.

     

    A local cache-only might be suitable and achieve some form of redundant opeartion.

     

    Ken Felix

    Steffen
    SteffenAuthor
    New Member
    October 15, 2021

    Hello Ken, thanks for your answer.

     

    unfortunately, there won't be a dns server in the secondary site. There is not enough place and no IT-staff.

    Which configuration would still be good for our situation? Can you recommend one to me?

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.