Created on
09-11-2023
10:56 PM
Edited on
09-12-2023
12:09 AM
By
Jean-Philippe_P
Description |
When using a dial-up SSL VPN with an iPhone (FortiClient-VPN APP) and an internal IP, it connects to the server normally. But when using FQDN, it cannot connect to the internal server which can be solved by the dns-suffix setting. This article describes how to assign an internal DNS server through the dns-suffix setting for iPhone. |
Scope | FortiOS 7.0, iOS. |
Solution |
Windows/Android platform dialup SSL VPN can connect normally to the internal servers by using FQDN with dns-server setting on SSL VPN to assign an internal DNS server.
iPhone will use a locally assigned (ISP assigned the public address) DNS server to send FQDN queries even the SSL VPN connected by FortiClient.
The public DNS server (ISP assigned) will never resolve the internal FQDN. Internal DNS server setting 10.1.218.5 for the FQDN thr.twtac.lab = 10.1.218.30.
SSL VPN connected:
The internal FQDN thr.twtac.lab failed to access but IP address:
Added the DNS suffix for the internal domain and re-dialup SSL VPN:
config vpn ssl settings
The internal webpage can be accessed by the FQDN:
|