FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nverma
Staff
Staff
Article Id 212362
Description This article describes how custom DNS servers are not supported with L2TP tunnels.
Scope FortiGate.
Solution

Custom DNS servers are not supported with L2TP tunnels. Users connected via L2TP will always retrieve FortiGate system DNS servers.


To change the configured DNS servers in GUI, Network -> DNS, then set the primary and secondary DNS servers.

 

With the CLI:

 

config system dns

    set primary x.x.x.x

    set secondary y.y.y.y
end

 

Changing the system DNS is a global change and does not affect only L2TP. The FortiGate will now use the configured DNS servers for DNS queries.

 

It is possible to configure custom DNS servers on the L2TP adapter in Windows by editing the Internet Protocol Version 4 (TCP/IPv4) settings.

 

Example:

 

control-panel-L2TP.jpg

 

When the L2TP VPN is connected, use ipconfig /all in Command Prompt or PowerShell to verify the custom DNS servers are configured.

 

L2TP-custom-DNS.jpg

 

Related articles:

Technical Tip: How to configure L2TP using interface/route based IPsec VPN

Technical Tip: Resolving Internet Connectivity Issues with L2TP IPsec VPN Using Windows Native Clien...

Troubleshooting Tip: L2TP in IPsec connectivity issues