VPN DNS Suffix issue FG200E v7.6.7
Hello,
I've been working on setting up an IPsec VPN on our FG200E after upgrading to FortiOS 7.6.7, mainly so we can take advantage of DNS suffix assignment from the firewall.
Our environment has two separate Active Directory domains in a trust relationship: old-domain and new-domain. In the config vpn ipsec phase1-interface configuration, I've defined DNS suffixes for both domains and configured the DNS servers with the old-domain DNS first and the new-domain DNS second.
Everything seems to be working correctly for resources in new-domain, but for anything in old-domain, I have to use the full FQDN to access it. This creates a major issue because some of our internal applications reference hosts by short name rather than a fully qualified DNS name.
We're currently using Cisco AnyConnect, and it works perfectly—users can access shares and applications using just the host name without any DNS resolution issues.
I've already opened a ticket with Fortinet, but I wanted to check if anyone else has run into this problem and, if so, whether they found a solution.
Thanks in advance!
