Skip to main content
ispcolohost
New Member
April 1, 2020
Question

Way to set DNS search domains after VPN setup, or push from FortiGate?

  • April 1, 2020
  • 3 replies
  • 9412 views

I'm running FG 6.2.3 and FortiClient 6.2 and am wanting to push my users a list of several FQDN's to treat as DNS search domains.  The problem is the Mac users whose default search domains disappear when connected via FortiClient, and I can't see a way in FG CLI to set more than a primary domain for an ipsec VPN.  Also, on the Mac side, given FortiClient does not create an interface in Networking, there doesn't seem to be a way to set search domains that do not get wiped when the VPN connects and resolv.conf is rebuilt.

3 replies

sw2090
SuperUser
SuperUser
April 2, 2020

Unfortunately in ipsec vpn you can onyl enter ONE domain.

you can enter up to 4 ipv4 and ipv6 dns servers

 

Also unfortunately fortinet has skipped one important option in gui and parly cli (you can set it on cli but you don't see it). With this option set to default you will always only get system dns pushed even if you entered your own ones.  I stumbled accross this for several times now. 

Also the domain option in ipsec is not availabe on gui.

 

You woould have to set it on cli:

 

  config vpn ipsec phase1-interface

  edit <phase1-name>

   set ipv4-dns1 xxx.xxx.xxx.xxx

   ...

   set domain "domain"

   set dns-mode manual

  end

to make it work...

ispcolohost
New Member
April 3, 2020

Ah, yep this was for ipsec, and I can't switch to SSL because they haven't figured out how to do dual stack over SSL VPN...

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.