Created on
01-23-2026
01:46 AM
Edited on
01-27-2026
05:19 AM
By
Jean-Philippe_P
| Description | This article describes the issue of DNS resolution not working over a remote access IPsec tunnel. It provides a step-by-step guide to resolving the issue by configuring the DNS suffix in the IPsec Phase 1 interface. |
| Scope | FortiGate. |
| Solution |
To resolve the issue of DNS resolution not working over a remote access IPsec tunnel, follow these steps:
By following these steps, the DNS suffix will be configured correctly, and DNS resolution should work as expected for short hostnames over the remote access IPsec tunnel.
The Cisco Unity Configuration Method extensions, which are related to this parameter 'unity-support', are specific to Cisco’s IKEv1-based implementation, so it is not possible to enable it when using IKEv2, and the option is hidden as a consequence.
Related article: Technical Tip: Unity-support is disabled after IKE version is changed from v2 to v1 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.