DNS Resolving from internal DNS Server over FGT to sub DNS_Server
have a very urgent problem. On the FGT I can resolve DNS names (e.g. mx.dom.com) that I have configured via an external DNS server. On the internal network we use MS-DNS and there I have entered the FGT as forwarder. When I try to resolve mx.dom.com from an internal system, it does not work (domain not found). In MS-DNS Event, I see: The DNS server encountered an invalid domain name in a packet from 192.168.30.9. The packet will be rejected. The event data contains the DNS packet. 192.168.30.9 is the FGT. Under Network/DNS Server, I have entered the internal port and the port of the external -DNS, optionally Recursive and Forward to System DNS. In the DNS Database, I have entered the domain mx.dom.com and through which DNS servers I can reach it.
Now it works, but it takes some hour, maybe it was a dns-timer.
But I have still the error messages on Domain Controller, "The DNS server encountered an invalid domain name in a packet from 192.168.30.9. The packet will be rejected. The event data contains the DNS packet."
I have now from FGT to intern DC in a Recursive Mode and for the other interface using the external DNS-Server Forward to System DNS.
On DNS-Database I have for the external System the IP of external DNS and for internal DNS our DC-DNS Server.
It's working now, but didn't know how to solve the error message.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.