Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tintis
New Contributor

DNS Suffix Deployment Issue on FortiGate Dial-Up IPSec IKEv2 VPN with Entra SAML and Intune Clients

Hi everyone,

Has anyone found a solution for deploying a DNS suffix to clients using a Dial-Up IPsec VPN with IKEv2 and Entra SAML authentication?

We’re using Intune-deployed clients without admin rights. I’ve tried using post scripts, but they seem to fail due to permission restrictions. I also attempted to push the DNS suffix via the EMS server, but I still can’t get it to apply to IKEv2 VPN tunnels.

Does anyone have an idea or workaround to make this work?

Thanks in advance!

2 REPLIES 2
Curtava
New Contributor

Turn on mode config and add the DNS suffix under internal-domain-list. No script needed. If you want to keep your files organized, I recommend cx file explorer for that.

mrsimon007
New Contributor III

I’ve run into this issue too — it’s tricky since IKEv2 tunnels don’t always inherit DNS suffixes cleanly, especially with Intune-managed, non-admin devices. One workaround is to push the suffix via Intune custom configuration profiles using PowerShell or OMA-URI settings before the VPN connects. Some admins also script it through Connection Manager profiles (CMAK) or apply it via a GPO that targets the VPN adapter once created. Would love to see if anyone’s found a cleaner Intune-only method though!

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors