| Description | This article describes an issue where FortiGate fails to generate logs for DNS queries from client machines when the DNS service is enabled using a Virtual IP mapped an internal interface IP address. |
| Scope | FortiGate v7.2.7, v7.2.8, v7.2.9, v7.2.10 and v7.4.5. |
| Solution |
When FortiGate has a DNS service enabled on an interface, and clients access the DNS server using a Virtual IP on the FortiGate, no DNS query log is generated. Although no log is generated, the FortiGate's DNS service receives the query and responds as configured.
Sample Configuration:
config system interface config system dns-server config firewall vip config firewall policy
This issue has been resolved in FortiOS version 7.6.1. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.