| Description | This article describes how to resolve an issue with a DNS server hosted on the other side of a firewall and connected via a tunnel where the local domain does not resolve. |
| Scope | FortiGate. |
| Solution |
Scenario:
A debug flow will be able to show you exactly what is happening to the packet, as long as it is entering the FortiGate. The commands that would be able to solve this issue are as follows: diagnose de flow filter addr x.x.x.x diagnose de en
More details and how to interpret this output can be seen here: Troubleshooting Tip: First steps to troubleshoot connectivity problems to or through a FortiGate wit...
Solution: To resolve the issue, update the existing policy route to direct DNS traffic through the VPN tunnel instead of the WAN interface. After re-configuring the policy route, the local domain will start resolving correctly, confirming that the traffic is being routed through the correct path via the VPN tunnel. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.