Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

DNS/Name Resolution over VPN tunnel

I have a FT100 at the home site and FG60 at the remote. I need to be able have name resolution work so the remote users can access Home office servers by name. tunnel is working. I can ping and use all other ports. I can create a HOST file and connect that way, but using HOST files everywhere is not desireable. Any ideas?
4 REPLIES 4
UkWizard
New Contributor

Dont understand the question ? Just get the remote users to use a DNS server at the other end ? Or are you saying thats what you have tried and it didnt work ?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Ok, I got it, they have to use the FQDN on the remote end to resolve. I needed to add a zone on my remote dns server. Netbios resolution does not work and I don' t have a Wins server onsite. don' t want one. DNS with FQDN should be fine.
UkWizard
New Contributor

Does this mean you tried this and it didnt work ? but it does if you use the fqdn ? In that case, when you set the dns in the clients TCPIP settings, pu the domain extension in there as well, then you wont need to specify the FQDN all the time. NOTE; if you want the remote users to also resolve internet domain names, say for web browsing without a proxy. Then the DNS server will need to be able to resolve these on there behalf.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Sounds good. I was trying to get away from having to configure each client' s dns settings. But if this is something I have to do that' s ok. I know the Symantec VPN client works a little differently. thanks!
Labels
Top Kudoed Authors