Created on
01-09-2015
04:33 PM
Edited on
11-28-2025
08:20 AM
By
Stephen_G
Description
To enable DNS registration option for SSL VPN clients when the FortiClient participates in FSSO, special steps must be followed.
Specifically, there is an additional registry value which needs to be changed.
Complete the Following Steps:
The same result can be achieved by modifying the <no_dns_registration>0</no_dns_registration> parameter on an xml file.The three possible states:
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Fortinet\FortiClient\Sslvpn]
"WinDnsCacheService"=dword:00000003
<dnscache_service_control>3</dnscache_service_control>
For example:
<?xml version="1.0" encoding="UTF-8" ?>
<forticlient_configuration>
<partial_configuration>1</partial_configuration>
<os_version>windows</os_version>
<vpn>
<sslvpn>
<options>
<enabled>1</enabled>
<dnscache_service_control>3</dnscache_service_control>
<!--0=disable dnscache, 1=do not tounch dnscache service, 2=restart dnscache service, 3=sc control dnscache paramchange-->
</options>
</sslvpn>
</vpn>
</forticlient_configuration>
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.