FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
iskandar_lie
Staff
Staff
Article Id 225434
Description This article describes how to Implement FortiGate as a Local DNS server database.
Scope FortiGate DNS feature. Version  6.4.10.
Solution

Scenario:

1) FortiGate will be used as a local DNS server database.

 

2) Global DNS server will be used to resolve global domain.

 

Local domain name : 40gate.co.id

DNS interface (port4) : 172.16.10.254

 

FortiGate DNS config: no firewall policy rule is required.

 

iskandar_lie_0-1664709960729.pngiskandar_lie_1-1664709994753.png

 

User testing:

 

Local DNS can successfully be resolved.

 

iskandar_lie_2-1664710046462.png

 

Global DNS can successfully be resolved.

 

iskandar_lie_3-1664710069298.png

 

DNS request process on FortiGate –-> for local entry, FortiGate will check its own database – cause FortiGate is aware of its local domain name.

 

'40gate.co.id'.

 

iskandar_lie_4-1664710144774.png

 

DNS cache: local entry database will not be cached.

 

iskandar_lie_5-1664710180053.png

 

Dumb DNS database.

 

iskandar_lie_6-1664710196863.png

 

Related documents:

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/960561/fortigate-dns-server

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/121810/using-a-fortigate-as-a-dns-server

https://community.fortinet.com/t5/FortiGate/Technical-Tip-DNS-database-with-FortiGate-as-a-slave-to-...

Technical Tip: Implement split DNS for Local and G... - Fortinet Community

Contributors