Description |
This article describes that when configuring DNS as the probing protocol on SD-WAN Performance SLA health check, FortiGate will send DNS A-record queries to the configured DNS server. |
Scope | FortiGate. |
Solution |
Use FortiGate's System DNS 'set system-dns enable' or specify a target DNS server.
Optionally, configure 'dns-request-domain' and 'dns-match-ip' (available under the CLI settings).
dns-request-domain<----- If not set, FortiGate queries example.com by default.
dns-match-ip<----- 0.0.0.0 by default, as long as FortiGate can query the DNS server with the 'dns-request-domain' and gets a DNS response, Performance SLA will be successful and the interface member state will show as alive.
config system sdwan set dns-match-ip 12.34.97.16
Packet captured for the DNS as probe protocol from FortiGate(10.47.1.37) to the target server (8.8.8.8):
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.