Description |
This article describes an issue where users are replicating an EMS Access topology in multiple FortiGates. One of the FortiGates is not working with the EMS access. |
Scope |
FortiGate. |
Solution |
Configuration. The following configuration can be seen in FortiGate
VIP configuration:
edit "Server"
Access proxy:
edit "Server"
To identify the issue, run the following debugs in the FortiGate :
SJOFW01 # di de console timestamp enable SJOFW01 # di wad debug enable category all SJOFW01 # di wad debug enable level verbose SJOFW01 # di de en
In the debugs, search for the wad_http_req_dns :
[V]2024-10-30 15:56:28.610184 [p:17042] wad_dns_parse_name_resp :323 domain.com: resp_type=0 notify=1 cdata=0 N/A
In the FortiGate DNS settings, public DNS servers are configured:
config system DNS
Solution: Change the FortiGate DNS server to the internal network DNS servers. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.