Skip to main content
David_Tan
New Member
September 18, 2018
Question

SSL VPN client cannot resolve by domain name

  • September 18, 2018
  • 8 replies
  • 37634 views

Hi.. i setup SSL VPN in my office. From home, i am able to connect to the VPN and i am able to visit sites by their direct IP. However i can get to the site by their domain name. We are running on an internal private domain within our network and the DNS server is the one provided within the Fortigate appliance.

 

At the moment, from within the SSL VPN setting page, i set the DNS entry in the tunneling mode client settings to "Use Client System DNS". Is that right? I felt that it is not but i am not sure what should be the right IP to use or even the right DNS entry to set.

    8 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    September 18, 2018

    Obviously you don't want to use that setting. There should be GUI on the FGT side to "specify" DNS server IPs to provide your internal DNS server IPs to clients when they get connected.

    David_Tan
    David_TanAuthor
    New Member
    September 19, 2018

    That is a default setting in the FG SSL VPN UI. The other option i have is to specify a DNS server but i am stuck here as i am not sure what is the IP i should use. The DNS server is running inside Fortigate itself. It is not a standalone DNS server.

     

    All my internal machine use their network's interface IP as the DNS server but i don't see an interface IP for SSL VPN. Am i missing it somewhere in the UI?  

    Ashik_Sheik
    New Member
    September 19, 2018

    Hi

     

    If fortigate is DNS server for inetrnal network then configure fortigate IP in teh DNS setting as local system dns and ssl dns .

     

    When configuring system dns keep primary dns as local and second dns as ISP or google dns .

     

     

    manojkanjookaran
    New Member
    February 18, 2023

    Hi There,

     

    I have a different scenario here . I use one of my internal machines on the LAN as DNS server. And I don't get the names resolved. However I can resolve all my internal machines through my local DNS server, but I am not not able to access any external websites. What could be issue ? Any help to resolve this problem would be much appreciated.

     

    Regards

     

    Manoj 

     

    Debbie_FTNT
    Staff & Editor
    Staff & Editor
    February 24, 2023

    Hey Manoj,

    did you set up any kind of DNS forwarding? If your internal DNS can't resolve a query, it sends it to another (external) DNS for a check?

    Without that, it would be impossible for your internal DNS to resolve all queries it gets.

    Please note that unless your FortiGate or another Fortinet product is acting as DNS server, we can't really help with figuring out what's going on with your DNS server.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.