Skip to main content
FortiDave
Explorer
October 12, 2022
Solved

Split DNS SSL VPN

  • October 12, 2022
  • 4 replies
  • 5592 views

Hi all,

 

I have clients using Android tablets where split tunneling is configured, and not working. Im pretty sure this is down to the DNS configuration on both client and Fortigate, rather than split tunnelling.

 

I can see all DNS requests going through the SSL interface.

 

Windows devices are working fine, as they seem to have internet DNS server on the adapter.

 

Ive found a lot of KB articles around split DNS, which have me a bit confused.

 

Im wondering could someone advise me on the clear steps required here to enable split DNS (assuming thats my issue), on the Android devices?

 

Of course I dont want to impact the current 500+ VPN users, so need to be mindful of any global DNS changes.

 

Thanks,

 

D

 

Best answer by FortiDave

Folks, apologies, this ended up being a routing issue on the internal network. Thanks for the input.

4 replies

gfleming
Staff
Staff
October 12, 2022

Check this documentation: https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/988717/ssl-vpn-split-dns

 

It should work for all endpoints regardless of OS.

FortiDave
FortiDaveAuthor
Explorer
October 13, 2022

Hi,

 

Below is my specific SSL portal configuration, which I believe looks correct. However, its still not working. I can see DNS queries traversing the FGT while testing internet access on the device, which just times out.

 

Is there anything I may be missing here? Could there be some global setting somewhere maybe?

 

Is there somewhere I can specificy 8.8.8.8 as DNS for clients internet requests, while connected to VPN?

 

Screenshot 2022-10-13 at 10.57.45.png

 

gfleming
Staff
Staff
October 13, 2022

OK let's get clear on the actual issue here. At first you mention split DNS is not working. And now you are saying Internet access is timing out. Split DNS would be used for internal queries. We can not dictate which DNS server to use for general internet queries when DNS split tunneling is enabled. 

 

So if internet is timing out there might be some other issue unrelated to split DNS. Also you say you see DNS queries traversing the FGT for Internet access which you shouldn't see with your split tunneling config.  

 

Have you tested the configuration without split tunneling and split DNS? This would tell you the VPN is working properly. Then you can turn on split tunneling and test that. And then move to split DNS.

FortiDave
FortiDaveAuthorAnswer
Explorer
October 14, 2022

Folks, apologies, this ended up being a routing issue on the internal network. Thanks for the input.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!