dns queries not coming through AFTER internet outage
Hi all
I am somewhat stumped about this issue and I am not sure where to start looking.
Problem:
There is an app with automatic checks to the internet which also automatically repeats dns queries to our internal dns servers. Those queries come from five or six source ports from each of the two IP addresses (the app runs on two servers) and there are quite a lot of those requests.
This app runs on a virtual machine which is connected to a fortigate 60F with 6.2.9.
The query goes to that firewall and then trough a VPN to another fortigate and from there to the DNS.
- If the internet goes offline for MORE than about five minutes and then comes back again, the automatic queries don't get an answer anymore (as if the DNS server never gets the requests).
- If the internet goes offline for LESS than five minutes, then there is no issue.
(I am not 100% sure about the exact amount of time).
Some more info:
- Unfortunately I have no firewall logs from that time it happens
- The customer is very reluctant about taking the branch offline again (so I am still planning more tests)
- There are no DNS filter security policies or any IPS or DoS policies (there are actually no UTM features licensed).
- The dns-session-helper is active.
Question:
Does anyone have an idea what I could check that might cause this issue (no response to automatic dns queries from this particular app after being MORE than five minutes offline)?
Thanks a lot
