| Description | This article describes how to resolve the issue when FortiClient iOS cannot resolve internal DNS after connecting to an IPsec VPN. |
| Scope | FortiClient iOS v7.4 and above |
| Solution |
Pre-requisite: Steps below will be useful when it is already tested that internal DNS works fine on FortiClient Windows, but it is not working properly in FortiClient iOS.
Sample IPsec VPN configuration:
config vpn ipsec phase1-interface end
The above DNS server configuration would work fine for FortiClient Windows, but not for FortiClient iOS. Due to iOS limitations, 'set internal-domain-list' is compulsory for FortiClient iOS to resolve internal DNS: config vpn ipsec phase1-interface end
After configuring 'internal-domain-list', FortiClient iOS can now resolve internal DNS. In this example, it could resolve FQDNs such as abc.domain1.com or companyA.domain2.com. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.