Description | This article describes how to set up the Address group for the Destination field on the Global DNS Policy if listening from an External interface. |
Scope | FortiADC, FortiADC-VM. |
Solution |
To configure the Destination address group in the Global DNS policy go to Global Load Balance -> Zone Tools -> Address group and select 'Create New'.
Note: This IP address has to be configured on the Interface level (it can be Primary IP or Secondary IP too). If it is not configured on the interface level, the DNS query will timeout.
If the Interface IP is used for some other purpose, use the Secondary IP under the Interface config.
Below is the Test result for the nslookup:
Nslookup test without using Interface IP (using IP from interface IP subnet):
Related document |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.