| Description |
This article describes how to restrict queries to a specific IP address with a DNS policy.
Secondary IP is configured in the network interface. DNS Zone and settings pre-setup. |
| Scope | FortiADC GLB. |
| Solution |
By default, when Global Load Balance is enabled, FortiADC listens to DNS queries with its network interface's physical IP address.
In some cases, the user requires a DNS zone to respond to queries using other IP address other than what is configured in the network interface, for instance, the secondary IP address.
Note: The configured DNS address group will be the destination as the query will always be an inbound connection. Select the respective DNS zone that will be applied with the policy.
Steps to verify:
dig @<ns-ip> <domain>
Successfully get the query answered from the FortiADC secondary IP address.
Query is refused from the FortiADC network interface IP.
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.