Skip to main content
mr_anderson
New Member
June 10, 2021
Question

Route issue to .local domain

  • June 10, 2021
  • 1 reply
  • 2513 views

We are currently in the process of removing Talari's from our environment and just having IPSec tunnels for AD traffic on the Fortigates. So far I have a couple offices moved over. We have a couple new offices with the same setup (minus the Talari) with IPSec tunnel(s). When doing a Route Lookup at the new offices to our .local domain, I get "No routes exists to the destination "DOMAIN.local". If I do it on the offices that were moved off the Talari device, it works fine and highlights the IPSec tunnel. I have compared the configurations and they are the same. I've looked at the firewall in our datacenter and everything appears to be identical with the new and old offices. DNS queries for the domain appear to be using the tunnel, but for my sanity I would like to figure why the route lookup at the old office locations but not the new ones. 

 

EDIT:

I ran a packet capture (not sure what diag debug command to use) and see that the DNS query is coming from 10.10.10.1 which is the DMZ interface. I looked and nothing is using the DMZ interface.

 

[image][/image]

1 reply

mr_anderson
New Member
June 11, 2021

I ended up figuring out the issue. I missed adding a source-ip under dns-database

 

config system dns-database edit "DOMAIN.local" set domain "DOMAIN.local" set type slave set authoritative disable set forwarder "*DNS server 1*" "*DNS server 2*" set source-ip *FORTIGATE LAN Interface* set ip-master *DNS server 1* next end

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!