Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JBruyet
New Contributor

Active Directory and Fortigate 80C

Hey all, I thought I had already posted this question but I can' t find it so if this is a double post please forgive me. I' m running a Windows Server 2003 Active Directory domain with three subnets. Per my vendor' s recommendation I originally set up my Fortigate to do my DNS and my DHCP services but NetBIOS names weren' t getting resolved. I dropped down to DHCP on the Fortigate and DNS on my Domain Controllers and that works for Forward Lookup requests but not Reverse Lookup requests. I was thinking about dropping DHCP from the Fortigate too but that would mean I' d need a second, redundant DC in each of my three subnets. I could whitebox them but I thought I' d ask here first to see what others are doing about this problem. Is anyone else successfully using their Fortigates for DNS and DHCP in Active Directory domains? Thanks, Joe B

Thanks, Joe B

Thanks, Joe B
1 REPLY 1
ChrisWessells
New Contributor

Joe, You can configure the Fortigate as a relay for DHCP and specify the DC as the DHCP server. In the switch configuration for each VLAN the switch must have the ability for dhcp helper which tells the device where to direct their DHCP requests. On the DHCP server setup multiple scopes based on the IP Subnets you want. The DHCP server knows what information to send in the response based on the IP address of the forwarding interface ie the internal interface of the vlan of which the request came from. You also may want to verify that you have the reverse lookup setup. If you don' t check the box to create a pointer record when you make static entries it will not create one. If you do not have the correct IP Address range defined in the DNS server, the pointer records (Reverse lookup) will not work. I hope this helps. I have 8+ VLAN behind an 80C and that is how I have it configured. It is working for me. Best Regards,
Chris Wessells Sr. Network Engineer
Chris Wessells Sr. Network Engineer
Labels
Top Kudoed Authors