| Description | This article describes the behavior of DNS status in an HA cluster. |
| Scope | FortiGate v7.2.x, v7.4.x and v 7.6.0. |
| Solution |
In a HA cluster environment, only the primary role unit would use the configured DNS server for name resolution. The standby role unit will use the primary unit for its name resolution
In the following example, FG01 is the primary unit, and FG02 is the secondary unit.
Below are the DNS settings.
From 'diagnose test application dnsproxy 2', FG01 shows the DNS servers:
On FG02, it shows 169.254.0.2, which is the IP of FG01 port_ha.
For example, when FortiAnalyzer Cloud is configured for cloud logging, the secondary FortiGate, even while in passive mode, continues to send DNS requests to the primary over the heartbeat link to resolve cloud service names. 2025-12-08 15:53:49.149080 port_ha in 169.254.0.2.3206 -> 169.254.0.1.53: udp 81 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.