Skip to main content
nl-bryan
Explorer
January 4, 2024
Question

FortiGate issue with 'Forward to System DNS' and local DNS database

  • January 4, 2024
  • 5 replies
  • 7642 views

Hi all!

 

I will try to keep this as clear as possible but I can't keep it short to be able to explain the full situation.

 

In short: Do DNS zones in the DNS database in a FortiGate take precedence over 'Forward to System DNS' when both System DNS servers are set to external hosts?

 

Extended version:

All VLANs in our office have their one and only DNS server pointed to our Fortigate. Recursive DNS is set up for three vlans (10,20,30). One vlan is set to 'Forward to System DNS' (vlan 40). Both system DNS servers point to public dns servers.

Two DNS-zones have been set up with forwarders to DNS-servers in our DC (over ipsec). One zone is for company.local, matching the primary zone for the domain controllers, another zone matches a public domain, company.nl, which is used for a few services that are available both internally and externally. Among those services is our monitoring server (monitoring.company.nl). This server is fully available over ipsec for management purposes and partly available via internet for monitoring purposes (multiple sites).

The subnets of vlan 10, 20 and 30 are included in the ipsec tunnel, whereas vlan 40 is not.

 

When clients in the vlans 10,20,30 resolve monitoring.company.nl, they receive an internal IP address, which is correct. This traffic then goes over the ipsec connection.

When the server in the separate vlan (40) tries to resolve monitoring.company.nl, it also receives the internal IP address while 'forward to system dns' is set for that vlan. The same behavior occurs when I try to resolve that address on the fortigate itself.

For now, the issue is solved by adding a rule to the local hosts file of the server in vlan 40 but I'm not a big fan of that.

 

I know there are multiple ways to solve this, like adding the subnet of vlan 40 to the ipsec connection or installing a separate probe at the server in vlan 40, but this behavior just started this morning after working fine for about 6 weeks.

I tried a couple of things with the 'diagnose test application dnsproxy' command or removing the zone company.nl, but then all clients in vlan 10,20,30 receive the external ip address.

 

Am I missing something here or is the 'Forward to system DNS' not as clear as it seems?

Thanks!

 

FortiGate v7.0.12

5 replies

Anthony_E
Staff
Staff
January 8, 2024

Hello Bryan,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
hbac
Staff
Staff
January 8, 2024

Hi @nl-bryan

 

FortiGate will check its database before 'Forward to system DNS'. If you don't want VLAN 40 to resolve internal IPs, you can set DNS servers of VLAN40 to be the public DNS servers instead of FortiGate. 

 

Regards, 

nl-bryan
nl-bryanAuthor
Explorer
January 8, 2024

That's what I figured, but this is something to think about right? I'm not in favor of pushing external DNS-servers to internal machines nor is it a best practice to alter the local hosts file. So a third option is to set up another internal DNS-server but yeah..

 

It's not a big deal in this case but I can imagine there are cases where you would like to have one vlan to resolve to an internal address and another vlan (e.g. guests) to go the other way around.

I'd say 'forward to system DNS' should skip the local database.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!