Skip to main content
ipranger
New Member
December 11, 2012
Question

[solved] Configure DNSforwarder

  • December 11, 2012
  • 8 replies
  • 4582 views
I hope this is the right section. What will come out? For example: When i' ve more then one locations i connect over vpn with an client (openvpn...). Until now i used local dnsmasq on a clientmachine. So i set an extra DNSserver for every Domain: 192.168.0.240/hello.local 172.13.12.240/fun.local ... So i can resolve every hostname. Ok. i would like to do the same with Fortigate. I' ve found something to configure DNSforwarding in the webinterface. But i dont have this option on my 60C. I searched for some CLI commands, but i do not found something helpfully. So how can i to this with my fortigate 60C? Greetings

    8 replies

    ddskier
    New Member
    December 11, 2012
    Make sure you have the " DNS Database" option checked under System->Admin->Settings. Once this is checked you will see new options under System->Network on the GUI.
    ipranger
    iprangerAuthor
    New Member
    December 11, 2012
    Hello ddskier This option was checked. I have already configured internal DNSservice and it works fine. But i dont have these forwardoption: http://docs.fortinet.com/fdns/html/wwhelp/wwhimpl/js/html/wwhelp.htm I hope it means what i' ve writen in my post.
    RetchedOne
    New Member
    December 19, 2012
    You do it from the CLI conf sys dns-server edit internal set mode recursive you can then create a dns database conf sys dns-database edit domain.com set forward 4.4.4.4 2.2.2.2 1.1.1.1 3.3.3.3 i did all my remote 60c' s thie way my local domain comes back across the vpn tunnel to the internal dns servers everything else uses the DNS on teh fortigate (public)
    RetchedOne
    New Member
    December 19, 2012
    conf sys dns-server edit internal set mode recursive end conf sys dns-data edit domain.local (your domain name) set domain domain.local set forwarder 1.1.1.1 2.2.2.2 (i chose two different dns servers across the tunnel) set type master set view shadow set authoritative disable set ttl 180 end point your dhcp server ont eh fortigate to hab out it' s internal interface ip for dns the keys here are to make the set mode recursive and on the dns-database set mode authoritative disable course all this cold blow your stuff up... so precede with a test...
    ipranger
    iprangerAuthor
    New Member
    December 22, 2012
    Thank you for you answer. I test this.
    ipranger
    iprangerAuthor
    New Member
    December 23, 2012
    Musst the fortigate have connection to this internal DNSserver from the other company? Because the fortigate has no connection to this DNS. Only the client who has the VPN.
    RetchedOne
    New Member
    December 26, 2012
    Yes, the firewall must have connectivity.
    ipranger
    iprangerAuthor
    New Member
    December 30, 2012
    I understand, then it can not work. Tanks for the information Greetings ipranger
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!