Skip to main content
rcpdkc
Explorer II
February 22, 2024
Solved

Fortinac-F DNS problem

  • February 22, 2024
  • 3 replies
  • 2176 views

I have a problem with Fortinac. Quarantine vlan defined in fortinac interface
Fortinac port 2 ip address
10.10.24.100

Quarantine vlan
10.10.22.10-10.10.22-250

I turned on vlan quarantine in Fortigate firewall
Gateway
10.10.22.1
DHCP relay 10.10.24.100
When I do this, a user who enters the quarantine vlan gets ip without any problem.
But my main problem is this
I have a domain and users log in with LDAP. However, in the quarantine vlan, the user cannot log in. It gives a domain error. If I manually enter the domain in the DNS section in the network settings, it gets better. But I cannot add DNS because DHCP distributes nac.
How can I solve this?

Best answer by AEK

You can fix this by adding domain controller FQDN as an allowed domain inFNAC.

Navigate to System > Settings > Allowed Domains, then add the FQDN.

Once done, when a client in isolation tries resolve FQDN's IP then FNAC provides the actual DC IP instead of 2nd FNAC's IP.

3 replies

rcpdkc
rcpdkcAuthor
Explorer II
February 22, 2024

Normally it should send the kerberos request to the domain, but fortinac sends it to 10.10.24.100 on port 2.

AEK
SuperUser
AEKAnswer
SuperUser
February 22, 2024

You can fix this by adding domain controller FQDN as an allowed domain inFNAC.

Navigate to System > Settings > Allowed Domains, then add the FQDN.

Once done, when a client in isolation tries resolve FQDN's IP then FNAC provides the actual DC IP instead of 2nd FNAC's IP.

AEK
ebilcari
Staff
Staff
February 23, 2024

You can use this articles to troubleshoot this more in depth and share your findings here:
Technical Tip: Troubleshooting domain resolution in the captive portal
Technical Note: Verify IP resolution of a domain when in isolation

Make also sure that the primary DNS of FNAC or the "Production DNS IP" in allowed domain is pointing to the private DNS, usually the DC itself.

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.