Skip to main content
davebell
New Member
November 21, 2022
Question

MacOS Ventura DNS Resetting

  • November 21, 2022
  • 12 replies
  • 12715 views

Hi,

 

I've recently upgraded my mac to Ventura, and I have a weird problem with the free FortiClient VPN.

 

I can connect fine, and to start with everything works as expected. After around 30-40 minutes however, DNS resolution for internal resources stops working.

 

Before it breaks I see the following:

 

scutil --dns DNS configuration  resolver #1 search domain[0] : xxx.net nameserver[0] : 172.17.0.5 flags : Request A records, Request AAAA records reach : 0x00000003 (Reachable,Transient Connection)  <... snip ...>  DNS configuration (for scoped queries)  resolver #1   search domain[0] : xxx.net   nameserver[0] : 172.17.0.5   if_index : 22 (en8)   flags    : Scoped, Request A records, Request AAAA records   reach    : 0x00000002 (Reachable)  resolver #2   nameserver[0] : 8.8.8.8   if_index : 14 (en0)   flags    : Scoped, Request A records, Request AAAA records   reach    : 0x00000002 (Reachable)  resolver #3   search domain[0] : xxx.net   nameserver[0] : 172.17.0.5   if_index : 27 (utun5)   flags    : Scoped, Request A records, Request AAAA records   reach    : 0x00000003 (Reachable,Transient Connection)

 

 

After it breaks I have instead

 

scutil --dns DNS configuration  resolver #1   nameserver[0] : 8.8.8.8   if_index : 22 (en8)   flags    : Request A records, Request AAAA records   reach    : 0x00000002 (Reachable)  <...snip...>  DNS configuration (for scoped queries)  resolver #1   nameserver[0] : 8.8.8.8   if_index : 22 (en8)   flags    : Scoped, Request A records, Request AAAA records   reach    : 0x00000002 (Reachable)  resolver #2   nameserver[0] : 8.8.8.8   if_index : 14 (en0)   flags    : Scoped, Request A records, Request AAAA records   reach    : 0x00000002 (Reachable)  resolver #3   search domain[0] : xxx.net   nameserver[0] : 172.17.0.5   if_index : 27 (utun5)   flags    : Scoped, Request A records, Request AAAA records   reach    : 0x00000003 (Reachable,Transient Connection)

 

 

While it is broken, my resolver is working just fine.

 

dig google.com @172.17.0.5  ; <<>> DiG 9.10.6 <<>> google.com @172.17.0.5 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18045 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1  ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; QUESTION SECTION: ;google.com.			IN	A  ;; ANSWER SECTION: google.com.		300	IN	A	142.250.200.46  ;; Query time: 50 msec ;; SERVER: 172.17.0.5#53(172.17.0.5) ;; WHEN: Mon Nov 21 16:32:15 GMT 2022 ;; MSG SIZE  rcvd: 55

 

 

It seems MacOS just decides to stop using the resolver provided by the VPN for some reason.

 

Has anyone got any clues about why this is happening, or where to look for clues as to why its happening?

I'm using VPN client 7.0.7.0245

12 replies

Anthony_E
Staff
Staff
November 24, 2022

Hello Dave,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Regards,

Best Regards
Anthony_E
Staff
Staff
November 24, 2022

Hello Dave,

 

I have found this guide which maybe can help you:

 

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/d09db1d6-1a69-11ed-9eba-fa163e15d75b/forticlient-7.0.7-macos-release-notes.pdf

 

Could you please tell me it it helped?

 

Regards,

Best Regards
davebell
davebellAuthor
New Member
November 24, 2022

Thanks for the link.

 

It doesn't really help. My issue is not listed in the known issues, and both fctservctl and FortiClient have full disk access enabled as instructed.

 

davebell_0-1669295574254.png

 

benjaminandresen
Visitor III
December 12, 2022

I'm having same issue since updating to Ventura.

Aeq
Explorer
December 26, 2022

Are there any news on this issue?
I am using IOS version of FortiClientVPN as a workaround however customers are complaining on this and I cannot offer them to use an unverified version.

adepretis
New Member
February 9, 2023

Hi,

a colleague of mine discovered, that disabling the IP tracking limiting feature seems to solve the problem:

Screenshot 2023-02-09 at 11.14.19.png

 

To be sure we disabled this for both WiFI and Network ports (even when not used) and it seems to work.

davebell
davebellAuthor
New Member
February 9, 2023

I've tried this today, and so far my DNS has not reset! Thank you!

 

If I have no further issues I'm going to mark this as the solution.

adepretis
New Member
February 22, 2023

OpenVPN has the same issues under Ventura and they fixed it ... maybe someone from FortiNet should look at this and implement a similar solution?

 

See: https://forums.openvpn.net/viewtopic.php?t=35018

---

We have released a new macOS OpenVPN Connect v3 build version 3.4.1 that enables a watchdog function for DNS settings. So if some process resets these DNS settings implemented by OpenVPN Connect, they should automatically be corrected again.

You can obtain the latest version here:
https://openvpn.net/client-connect-vpn-for-mac-os/

---

recursiveiterator
New Member
March 5, 2023

In my case, the trigger for the primary resolver entry going back to the local (non VPN provided) state is any wifi reconnect, which is often invisible to the user. The laptop hops from one AP to another, mDNSResponder pushes the local DNS server to be the primary resolver, VPN DNS gets broken.

 

FortiClient must either block those updates or monitor them and restore VPN DNS settings every time they occur.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.