Question
DNS resolution with IPSEC VPN
Hi! I am having some problem with the DNS resolution on our remote branch. We have two fortigate 60B, connected via IPSEC VPN, with the DNS server in our office, remote branch could not ping our servers here via its name (ping MYSERVER --unable to resolve host). FG60B-V3.0MR7 build 0750 Network is set up this way: (Internal Interface- Head Office) 192.168.1.0 ---IPSEC VPN --- 192.168.2.0 (Internal Interface - Remote Office) Remote Branch have two Internet Link, with policy route being configured. Internal to WAN1 (where IPSECVPN is set-up: src:192.168.2.0/24 - dst:192.168.1.0/24 Internal to WAN2 (pure Internet traffic) src:192.168.2.0/24 - dst: 0.0.0.0/0.0.0.0 Already created policies on both devices, the Head office can ping network on 192.168.2.0 and also the remote office to 192.168.1.0 by using IP address. Head office can ping the server by its name (MYSERVER) which is of the same network (192.168.1.0). By the way, remote branch does not have DNS Server (few PCs) only and using the FG60B being set-up as their DNS Server on their PC. I have tried using the DNS Server on the head office for the remote branch but doesn' t work. Internet however is working fine on the remote branch. What am I missing here or mistakes on my config? Any help is highly appreciated. Thanks a lot! --mix
