Ever since the firewall was set up, the DNS to contact the domain hmf.local is not working. Does the firewall inspect internal DNS queries? The local DC is the DNS server and FG is the DHCP server. The DC can be pinged from workstations. The FG is connected to the DC via LDAP.
For e.g., This stops VPN users from changing their passwords remotely.
This stops Windows machines joining domain.
If they're in the same subnet/interface, the devices' DNS query packets don't even hit the FGT based on your diagram. It would just directly hit the DC/DNS server via the switch. Then the server directly returns the replies to the device.
You can sniff the DNS traffic at either the device or the server with Wireshirk.
Toshi
User | Count |
---|---|
2597 | |
1382 | |
801 | |
663 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.