DNS Server
I have two Fortigate devices: FG1 and FG2. There's a tunnel between them, with a computer connected to the LAN port on FG1 and a file server on FG2. I would like FG1 to resolve the domain to an IP address, which is why I set up a DNS server on FG1. Now, the question is: what should I enter in the DNS Forwarder, and should I check "authoritative"? I don't know what that means, but I think I should check it because I don't want the query to go to the internet, but rather to stay within my network.
The DNS forwarder is set to 8.8.8.8, and it works, but I don't know why. If I set the DNS forwarder to 8.8.8.8, I understand that addresses not found in the local database will go to the internet. But why does it work if I'm setting up a new zone? Shouldn't this option be in DNS Service on the interface, not in the DNS database? And when I add a second zone because I want it to resolve another domain, what should I enter in the DNS forwarder? When I leave it blank, everything still works, including public DNS (like Google's) as well as the local one I configured.
How does this work exactly? I can't find a clear explanation anywhere, and what should I do according to your advice?
