This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.
I have recently deployed a 60 series with SSL VPN configured. The VPN is working great until we tried to proxy web traffic (no split tunneling) through the Fortigate. The internal IP address of the Fortigate provides DNS services successfully for those on the LAN, but VPN users get no DNS response.
To test, I deployed an internal DNS server on the LAN, set its forwarding address to the Fortigate (so it is a DNS proxy) and set the VPN to use the DNS server. VPN client can now resolve both internal and external DNS names.
Does anyone know what it takes to get VPN users to use the internal DNS services of the Fortigate?
We're having the same issue I think. I know on our end the internal uses the .1.0 subnet which some many home/public connections uses she it causes us issues. One thing that helped for us was enabling VPN before logon and logging in that way to force the connection over the VPN for routes and DNS.
ím having a case open but still with first level.
using 5.6.2 and under windows with the default setting and forticlient 5.6.x, all DNS queries are sent to the client DNS server. Definitely unwanted behavior.
with ios 11 and forticlient 5.4.4.x the client dns server queries are sent into the tunnel but it means no responses.
my goal was that i can define the „same as Interface IP“ on ssl.root and then define under dns server forward ssl.root to system DNS.
but that did not work, option does not exist.
for me the option of same as client DNS does not make sense, and defintely the behavior difference on windows and ios is unwanted.
using the client dns only makes sense for split dns, split tunnel designs, but as always there might be other use cases, but nobody lists them all.
My last hope is to use specify and point to an IP address that is then the DNS of FGT, but I dońt know how, the DNS server of FGT seems not to be able to run on its own ip, most probably qny interface IP will work ..... not sue going to twst it now, my ssl vpn users on ios cannot access the internet.
but maybe i did it wrong again ;((
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.