Skip to main content
ghani
New Member
September 13, 2021
Question

DNS suffix configuration in IPSec phase1-interface

  • September 13, 2021
  • 1 reply
  • 3081 views

I have a problem that DNS resolution doesn't on my IPsec VPN tunnel. I have seen online that I need to "set domain" in my IPSec phase1-interface configuration. However the command "set domain <domain.xyz>" is not available. I have already enabled mode-cfg. Could you please give me any tips on how can I achieve this? I am using fortogate v6.4. 

1 reply

sw2090
SuperUser
SuperUser
December 30, 2022

I had issues with DNS not working in IPSec too. The culprit was that I did set DNS Server(s) and also did set the suffix but the DNS mode was still at auto. Since I did set that up in FortiManager that might have been a bug in FMG.

But also that could mean that you have to set the DNS mode on your p1 to "manual" to make the domain option available...

 

hth

Seastian

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.