Skip to main content
CHR57
Explorer II
January 20, 2022
Question

SSL VPN DNS problem

  • January 20, 2022
  • 2 replies
  • 2969 views

When I connect by SSL-VPN with Forticlient and I do a Nslookup I get this DNS time out;

nslookup ad2.office.local
DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: 10.300.2.2

Name: ad2.office.local
Address: 10.300.2.3

 

When I do it locally it answers without any problems;

nslookup ad2.office.local
Server: AD1.office.local
Address: 10.300.2.2

Name: ad2.office.local
Address: 10.300.2.3

 

I can from SSL-VPN ping office hosts by DNS name.

Split Tunneling with DNS Split Tunneling is enabled to office.local 10.300.2.2 and 10.300.2.3.

On the SSL client, I have both the office DNS and my local DNS (from ISP).

My SSL-VPN Settings DNS are pointing to my office DNS (10.300.2.2 and 10.300.2.3).

SSL-VPN policy is opened from SSL-VPN to the DNS.

 

FortiOS 6.4.8

Forticlient 7.0.2

 

2 replies

TonyJones
New Member
February 1, 2022

Follow the simple steps here. Hopefully, it will help you.

CHR57
CHR57Author
Explorer II
March 11, 2022

Solved by turning off DNS slitting.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!