This article describes the steps to create an additional Winbind instance in FortiNAC that connects to a different domain and its respective Domain Controllers. The reason why the configuration of Winbind is required in FortiNAC is explained in this article: Technical Tip: MSCHAPv2 authentication, join FortiNAC in domain and checks.
The same steps can be followed to configure the DNS server used by FortiNAC, in case the required DNS records are missing. In environments that have only a single domain, the DNS server configured in FortiNAC is often one of the domain controllers, which typically has all the required DNS records preconfigured by default.
Note:
If there are multiple Domain Controllers but they are used for the same domain, these steps are not required; all the DCs should be automatically discovered and used in rotation.
FortiNAC.
The DNS server that is used by FortiNAC is configured in the 'Config Wizard' during initialization. This configuration can be later changed by going in System -> Config Wizard -> Basic Network -> DNS. A reboot of the appliance is required to apply the changes.
Due to the nature of Winbind and the compatibility requirements by Microsoft, some specific DNS records need to be configured for the Winbind instance to successfully join the domain. More details are shown in this section of the Microsoft server website: How to verify that SRV DNS records have been created for a domain controller.
In this example, FortiNAC is using the first Domain Controller as its DNS server, which also hosts the domain 'eb.eu'. The Winbind instance is already created and working for this domain without any extra configuration on the DNS server. The requirement is to add a second Winbind instance pointing to the domain 'eb.lab', which is hosted in another Domain Controller. For this configuration to work, the DNS server (10.1.1.10) should include at least the following DNS records pointing to the second domain and Domain Controller (10.6.1.10):
And a normal DNS A record for the second Domain Controller itself:
Checks done from FortiNAC CLI:
execute enter-shell
Related articles:
Technical Tip: MSCHAPv2 authentication, join FortiNAC in domain and checks
Troubleshooting Tip: Local Winbind configuration fails to start
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.