Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ranjith1
New Contributor

Add Multiple DNS IP in Fortigate Fw

Dear Team,

 

Currently, we are using the 1200D firewall in our corporate office.  In the Box, we have created multiple ADOMs and multiple ISP links as well. Hover, we are facing the issues in DNS lookup field error in the sum of the websites. And we have already configured Global VDOMs in global DNS like 8.8.8.8 and 4.2.2.2. 

But, when we are facing the issue of a DNS lookup failed error, we have to change the DNS IP as per the ISP providing the own DNS IPs. 

Could you tel me any option available in FortiGate to configure the multiple DNS IPs?  If the option it's available please

 

ranjith
ranjith
14 REPLIES 14
IT_Ahan2
New Contributor III

what are the current DNS Ips ?

Ranjith1

Current DNS IP 8.8.8.8 and  4.2.2.2

ranjith
ranjith
Mohamed_Gaber
Contributor

Does it work for the Global VDOM?

"we have to change the DNS IP as per the ISP providing the own DNS IPs"; It seems the ISP is blocking DNS requests to other DNS servers.

Could FortiGate itself resolve DNS and access FortiGuard?

Mohamed Gaber
Cell : +201001615878
E-mail : mohamed.gaber@alkancit.com
Mohamed GaberCell : +201001615878E-mail : mohamed.gaber@alkancit.com
Ranjith1

Ya, We tried Foriguard DNS also, It's getting more latency compared with google DNS.

 

Do you have any settings required for the DNS configuration in VDOM? 

ranjith
ranjith
Mohamed_Gaber
Contributor

"It's getting more latency compared with google DNS"; The latency occurs with google DNS or ISP DNS?

Mohamed Gaber
Cell : +201001615878
E-mail : mohamed.gaber@alkancit.com
Mohamed GaberCell : +201001615878E-mail : mohamed.gaber@alkancit.com
Ranjith1

The latency occurs when we configure the Fortiguard DNS. Currently, ISP DNS is not configured. In Fortigate only 2 options are available Primary and secondary. Now we have configured the google DNS.  

ranjith
ranjith
Mohamed_Gaber
Contributor

"The latency occurs when we configure the Fortiguard DNS"; It seems that FortiGate could not access FortiGuard.

Configure the ISP DNS and try to execute ping to a site from FortiGate CLI and nslookup from the client's CMD.

Mohamed Gaber
Cell : +201001615878
E-mail : mohamed.gaber@alkancit.com
Mohamed GaberCell : +201001615878E-mail : mohamed.gaber@alkancit.com
Mohamed_Gaber
Contributor

config system dns
set primary <ISP DNS>
set secondary 8.8.8.8

end

Mohamed Gaber
Cell : +201001615878
E-mail : mohamed.gaber@alkancit.com
Mohamed GaberCell : +201001615878E-mail : mohamed.gaber@alkancit.com
Ranjith1

Hi, we have the 3 VDOM. in all VDOMs we have 3 ISP links. How to configure the per VDOM DNS? 

ranjith
ranjith
Labels
Top Kudoed Authors