| Description | This article describes how to implement the FortiGate DNS database feature with FortiClient ZTNA. |
| Scope | FortiGate, FortiClient, FortiClient EMS. |
| Solution |
The managed version of FortiClient can proxy traffic to FortiGate through ZTNA. FortiClient uses ZTNA destinations to decide which traffic needs to be proxied to the FortiGate. In some scenarios, it's required to use an internal FQDN to access internal resources. As a solution, FortiClient can send a DNS query to the FortiGate DNS database to resolve the FQDN and use ZTNA.
This article assumes that ZTNA is functioning and endpoints can already access ZTNA resources through an IP address.
Troubleshooting ZTNA and FQDN errors.
Error Code: 023
Matching.
It is also beneficial to ensure that FortiClient is sending the DNS request to FortiGate. This can be checked through the fortitcs.log file under C:\Program Files\Fortinet\FortiClient\logs\trace.
The nslookup command should indicate that FortiClient is using 10.235.0.1 as a DNS server. If the nslookup command still shows the normal DNS server configured on the endpoint, check that the ZTNA destination FQDN matches exactly with the nslookup command. It is also useful to check that FortiClient is connected to EMS and to confirm that the ZTNA feature is enabled. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.