Skip to main content
aseques
Visitor III
July 21, 2022
Question

Disable setting DNS for a forticlient portal

  • July 21, 2022
  • 5 replies
  • 4097 views

We are using tunnel mode VPNs on our firewall. Now there's a subset of users that need to use another vpn client from another vendor as their main VPN while retaining our VPN client for som other uses.

I tried setting the dns-server1 / dns-server2 inside "config vpn ssl web portal" but it doesn't seem to have any effect because the VPNs still have the default dns pushed (not the ones set by me)

The desired effect would be to disable setting the DNS entirely in this case (but intermediate solutions might work)

 

Reading through the documentation I've found this (https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-DNS-servers-per-SSL-VPN-Portal/ta-p/194780) but it says that "Specifying the DNS server settings at the portal level is overriding those at the global level." and it doesn't seem to work in my case (it's because I'm using tunnel mode??)

 

Any ideas?

5 replies

Anthony_E
Staff
Staff
July 24, 2022

Hello aseques,

 

Thank you for using the Community Forum.

 

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Best Regards
Anthony_E
Staff
Staff
July 25, 2022

Hello aseques,

 

Could you please indicate under which version your units are running?

I will then check if there is another documentation.

 

Regardsm

Best Regards
aseques
asequesAuthor
Visitor III
July 25, 2022

Hi Anthony,

 

The version I have in those units is FortiOS v6.2.9 build1234 (GA)

 

Anthony_E
Staff
Staff
July 26, 2022

Hello aseques,

 

Meanwhile I am asking some support, could you please check this document?:

 

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/960561/fortigate-dns-server

 

Regards,

Best Regards
aseques
asequesAuthor
Visitor III
July 27, 2022

Hi @Anthony_E  I read through that page, it's related to the DNS system for fortigate, I'm interested on the DNS sent to de VPN client, that isn't covered on that page.


Thanks