Skip to main content
Yogev
New Member
September 19, 2019
Question

fortigate - forward all network traffic through specific dns server

  • September 19, 2019
  • 1 reply
  • 2610 views

Hello,

I will like to forward all DNS queries at my network to go through a safer DNS server like 9.9.9.9. This is the current configuration - My DHCP server is the FortiGate and it is directed to a DNS server at my network. I will like to keep the DNS server as it is but instead of sending the queries to my ISP DNS server I want it to run through the quad9 DNS server. Any ideas?

    1 reply

    ede_pfau
    SuperUser
    SuperUser
    September 19, 2019

    Create a VIP which redirects (destination NAT) your ISP's DNS address to quad9.

    external address: 1.2.3.4 (your ISP's DNS)

    mapped-to: 9.9.9.9

     

    no port forwarding.

     

    Then, create a policy

    from LAN

    to WAN

    src addr LAN/24

    dest addr: this_VIP

    service: DNS

     

    and query with "nslookup" from a host.

    I use this to reduce NTP queries by redirecting them to the FGT LAN interface, and using the FGT as NTP server. Sometimes this is easier than walk around and change so many devices...

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!