FortiGate issue with 'Forward to System DNS' and local DNS database
Hi all!
I will try to keep this as clear as possible but I can't keep it short to be able to explain the full situation.
In short: Do DNS zones in the DNS database in a FortiGate take precedence over 'Forward to System DNS' when both System DNS servers are set to external hosts?
Extended version:
All VLANs in our office have their one and only DNS server pointed to our Fortigate. Recursive DNS is set up for three vlans (10,20,30). One vlan is set to 'Forward to System DNS' (vlan 40). Both system DNS servers point to public dns servers.
Two DNS-zones have been set up with forwarders to DNS-servers in our DC (over ipsec). One zone is for company.local, matching the primary zone for the domain controllers, another zone matches a public domain, company.nl, which is used for a few services that are available both internally and externally. Among those services is our monitoring server (monitoring.company.nl). This server is fully available over ipsec for management purposes and partly available via internet for monitoring purposes (multiple sites).
The subnets of vlan 10, 20 and 30 are included in the ipsec tunnel, whereas vlan 40 is not.
When clients in the vlans 10,20,30 resolve monitoring.company.nl, they receive an internal IP address, which is correct. This traffic then goes over the ipsec connection.
When the server in the separate vlan (40) tries to resolve monitoring.company.nl, it also receives the internal IP address while 'forward to system dns' is set for that vlan. The same behavior occurs when I try to resolve that address on the fortigate itself.
For now, the issue is solved by adding a rule to the local hosts file of the server in vlan 40 but I'm not a big fan of that.
I know there are multiple ways to solve this, like adding the subnet of vlan 40 to the ipsec connection or installing a separate probe at the server in vlan 40, but this behavior just started this morning after working fine for about 6 weeks.
I tried a couple of things with the 'diagnose test application dnsproxy' command or removing the zone company.nl, but then all clients in vlan 10,20,30 receive the external ip address.
Am I missing something here or is the 'Forward to system DNS' not as clear as it seems?
Thanks!
FortiGate v7.0.12
