Skip to main content
lrodia
Visitor III
March 1, 2024
Question

FortiClient SplitDNS Issues

  • March 1, 2024
  • 2 replies
  • 4411 views

We have laptops running Windows 10 / Windows 11 running FortiClient version 7.2.3.0929.  We have a handful of clients that are having issues with splitDNS....I have had Fortinet confirm my splitDNS configuration on our FGT100F running 7.4.3.

 

Has only else had similar issues or have an idea where I can start?

2 replies

AEK
SuperUser
SuperUser
March 2, 2024

Try follow this guide.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-SSL-split-tunnel-and-split-DNS-work/ta-p/257081

On the other hand did you try resolving with nslookup instead of web browser? Sometime browsers are configured for DNS over SSL/HTTPS and I don't really know if this works with split DNS.

AEK
lrodia
lrodiaAuthor
Visitor III
March 5, 2024

Hi AEK, 

Yes, we tried nslookup and you can see that it seems to use the ISP DNS servers.  You are able to ping the DCs and if you use nslookup but tell nslookup (nslookup <fdqn> <company dns server) to use the company dns servers it will resolve the name, it is almost like there is a preference.  When you do an ipconfig /all you can see that the VPN interface does not populate the splitdns server addresses either.   I will take a look at the guide in case something I can tweak....what is interesting, myself running the latest client do not see any of these splitDNS problems and I am also running Windows 11, but my colleague who is also running Windows 11 is seeing this issue all the time to the point he now uses a local host file to add the entries so he can work. We also tried an older client (7.2.1.0779) which we were told may help but he has the same issue.

AEK
SuperUser
SuperUser
March 5, 2024

Hi Rodia

That's interesting.. Same OS and same client version but different behavior, then I think it may be related to some OS patch difference between the two hosts. As stated in the shared tech tip: "This may occur due to the operating system driver" (which can be changed by a patch).

AEK
hbac
Staff
Staff
March 2, 2024

Hi @lrodia,

 

Can you provide more details about the issue? VPN users are not able to resolve internal domain names? Have you tried FQDNs instead of host names? 

 

Regards, 

lrodia
lrodiaAuthor
Visitor III
March 5, 2024

Hi hbac,

 

Yes, we have tried both fqdn and non fqdn, for me both work but some of my colleagues splitdns will not work.  For example, the images show my colleague trying to resolve a fqdn address of the domain controller (dns server) but failing, but when using the IP of the domain controller (dns server) it resolves, ironically itself, you can see the failed attempt seems to use their routers gw for dns.  

 

You can see when I do this either using the IP or the fqdn of the domain controller it works either way.  This is the same for any host my colleague tries, sometimes he may get the odd occasion where splitDNS is working but its very rare which is why he has started to use local hosts file until we can resolve the issue.  We currently have around 5-10 clients reporting this, these are probably heavier users of the VPN but I have heard more reports, but those users are able to work around the problems.

93e39b97-3761-42e0-93fb-bef9a67ba216.jpg9db91b5b-d5ce-4afa-82aa-c809cf90813a.jpg

 

 

 

 

 

 

 

 

hbac
Staff
Staff
March 5, 2024

@lrodia,

 

It might be a known issue with FortiClient 7.2.3. Please refer to https://docs.fortinet.com/document/forticlient/7.2.3/windows-release-notes/991883/known-issues

 

909244

SSL VPN split DNS name resolution stops working.

 

Regards,