Description | This article discusses the DNS forwarder works. |
Scope | FortiGate DNS forwarder. |
Solution |
1) Two DNS forwarders are configured it will always use the first one. 2) If no response is received from the first one for five seconds it will try the next one on the list. 3) It will not work as a round robin when two DNS forwarders is in use. PCAP shows the 1st list in DNS forwarder does not respond:
No. Time Source Src Port Destination Dst Port Protocol Length Info 8337 2023-04-15 18:17:33.232349 10.176.3.124 2763 10.176.1.12 53 DNS 77 Standard query 0x0004 A 852ww.example.com
4) When the first one is down the FortiGate will direct forward the DNS request to the second IP in approximately 25 seconds:
No. Time Source Src Port Destination Dst Port Protocol Length Info 8337 2023-04-15 18:17:33.232349 10.176.3.124 2763 10.176.1.12 53 DNS 77 Standard query 0x0004 A 852ww.example.com
Note: There will be no impact at all in the beginning when 1st forwarder is down because the DNS requests will send to the secondary forwarder if there's no reply from 1st forwarder. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.