Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fgmaster
New Contributor II

Cannot contact local domain

Ever since the firewall was set up, the DNS to contact the domain hmf.local is not working. Does the firewall inspect internal DNS queries? The local DC is the DNS server and FG is the DHCP server. The DC can be pinged from workstations. The FG is connected to the DC via LDAP.

 

For e.g., This stops VPN users from changing their passwords remotely.
This stops Windows machines joining domain.

10 REPLIES 10
Toshi_Esumi

If they're in the same subnet/interface, the devices' DNS query packets don't even hit the FGT based on your diagram. It would just directly hit the DC/DNS server via the switch. Then the server directly returns the replies to the device.
You can sniff the DNS traffic at either the device or the server with Wireshirk.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors