This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.
Hi you'll
Been trying this for a while now. In our office we have a HA cluster of 2 92D. I'm running a nettwork there based on MS servers with 2012R2 domain controllers and DNS. I got a couple remote site's connected with 60D boxes. i setup a Ipsec tunnel that works got and very stable. On the remote sites I use DHCP and need to setup my DNS servers at HQ as the DNS to be able to resolve my servers at HQ, Side effekt is that those DNS servers have to resolve all trafikk. I've been trying to sett up DNS server on the 60D boxes so that everything is handled at the local 60D box.
I activated DNS on the internal interface and tried both recursive and non recursive and of course i setup the DNS SERVER on the box to answer for the HQ domain, put op the right IP for the master set type to slave and view as shadow and authoritive to enable.
Doesn't seem to work :( so I most humbly ask for some guidance.
Rene
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Thx for your reply .
I tried it, deleted and tried again to no avail, feel kind of stupid.
Seems that it doesn't find the "DNS server" on the 60D box. i set up as splitt DNS and followed both suggestions. Nothing get's resolved if i use nslookup in the domain (machine.domain.no) when i do a nslookup and specify the DNS server works like a dream. So I'm back to using my DNS server's from HQ provided through DHCP.
As said feel a bit stupid.
Rene
THX Tony.
that did the trick. Suddenly i realised what you meant with source-ip works like a dream now.
PS the DNS-server setting is recursive, forward-only didn't work
Again thx for your help and insight
Rene
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.