We are replacing a Linksys Router with a Fortigate Fos 6.2.7.
I just want to get NAT up and running so our users can get internet access. Later we will be setting up VPN Groups.
Currently, when we switch our ISP modem over to Fortigate everyone loses their internet access.
The problem I can find is on the DNS GUI both DNS servers (from the ISP) are UNREACHABLE.
I have attached my IPv4 Policy for NAT service.
What am I missing here?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
your policy sounds right.
what do your clients use as DNS Server?
If they use the FGT as DNS Server you might need to enable DNS Forwarding for the interface.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Your policy is way too simple to cause such troubles, look more closely at the connectivity between FOrtigate and ISP modem/IPS network.
[ul]
Hi 619Hiker,
As Yurisk has said about- check those basic steps first.
Also, are you using DHCP for clients?
I presume you are (for a small network) in which case how have you set up your DNS servers under the DHCP settings for the interfaces your are using?
If you are specifying the "local interface" or "system DNS" in the DHCP settings then you will also need to add a DNS server to the interface. DNS Services on an interface are not enabled by default. See the 6.2.7 cookbook for details here:-
https://docs.fortinet.com/document/fortigate/6.2.7/cookbook/960561/fortigate-dns-server
I have been caught out with this issue myself in a hurry to bring up a Fortigate so worth reading and understanding this reference perhaps?
Good luck- hope that helps.
Kind Regards,
Andy.
Thank you all for the replies.
Our Domain controller handles the DHCP for all our clients. So this service is not enabled on the Fortigate.
Currently, our clients have the following DNS servers;
DNS1 192.168.1.200 ( this is our DC )
DNS2 8.8.8.8
DNS3 8.8.4.4
When I make the switch from our old router to the Fortigate, should I also restart the ISP modem?
OH wow, so while I was reviewing the DNS server on my clients, I see that their Default Gateway is 192.168.1.1
I have my fortigate's local IP as 192.168.1.2 ( DUH ! )
I will test again Thursday and I'll change my Fortigate's IP to match the default gateway IP 192.168.1.1
Sorry - Hope I didn't waste much of anyone's time.
Did anybody notice that the WAN link in your screenshot is DOWN? No link, no internet.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.