FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
hhasny
Staff
Staff
Article Id 365942
Description This article describes the behavior of DNS status in an HA cluster.
Scope FortiGate v7.2.x, v7.4.x and v 7.6.0.
Solution

In a HA cluster environment only the primary role unit would use the configured DNS server for name resolution. The standby role unit will use the primary unit for its name resolution

 

In the following example, FG01 is the primary unit and FG02 is the secondary unit.

 

get sys ha statusget sys ha status

 

Below is the DNS settings.

 

FG01 DNS settingsFG01 DNS settings FG02 DNS settingsFG02 DNS settings

 

From 'diagnose test application dnsproxy 2', FG01 shows the DNS servers:

 

FG01 diagnose test application dnsproxy 2FG01 diagnose test application dnsproxy 2

 

On FG02, it shows 169.254.0.2, which is the IP of FG01 port_ha.

 

FG02 diagnose test application dnsproxy 2FG02 diagnose test application dnsproxy 2

 

Contributors