DNS Server - Answer for specific records and forward for all others in a zone?
I have the following use case with Fortigate 6.4.12:
I have a DNS domain hosted with my ISP for internet facing service say myorg.com. Therein I have several hostnames for services. I need to split-brain only specific hostnames under this domain internally on my corporate LAN. For example
- When www.web.myorg.com is resolved from the internet I wish to give 1.1.1.1
- When www.web.myorg.com I wish to return 2.2.2.2
- When anything underneath it (host.www.web.myorg.com etc.) is resolved I wish to forward to another set of DNS servers
Internally on my corporate we use Windows DNS servers. Whilst these support conditional forwarding catering for 2 and 3 is messy and requires multiple upstream DNS servers.
Can the Fortigate DNS servers setup with non-authoritative zones simply answer for specific records and forward for all others in a zone?
