Created on
05-08-2020
03:23 AM
Edited on
12-21-2025
10:43 PM
By
Jean-Philippe_P
Description
This article describes how to configure a single DNS server IP from the GUI.
Scope
FortiGate.
Single DNS configuration while using the IPSEC wizard tool.
DNS configuration in existing IPSEC tunnel.
Solution
Edit the VPN tunnel from CLI.
config vpn ipsec phase1-interface
edit <vpn name>
set dns-mode manual
set ipv4-dns-server1 3.3.3.3
set ipv4-dns-server2 4.4.4.4
end
The dial-up VPN client will get 3.3.3.3 as the primary and 4.4.4.4 as the secondary DNS server.
Note: The GUI only displays ONE DNS field.
set ipv4-dns-server3
If split tunneling is enabled and internal DNS servers are used, ensure that the configured DNS server IP addresses are included in the accessible (split-tunnel) networks. Otherwise, DNS resolution for internal resources will fail since traffic to the DNS servers will not be routed through the VPN.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.