I have a guest network which is routed to the internet via a seperate vlan on the wan side.
The guest network uses a a captive portal on a different network, in order to implement https for the captive portal i need clients to dns resolve the CP url, this i can do with a dns database on the FG and setting dhcp to use the FG interface for dns.
This works fine except for one thing.
Forwarding uses the DNS servers configured on the FG, the forwarders configured on the dns database only work for that domain, all other dns lookups use the box dns servers. This is a problem that creates a lot of extra configuration work arounds.
The Question is. Is it possible to define specific DNS forwarders for a specific vlan/net and not use the 'default' DNS servers configured on the box which are used for all other non-guest network DNS?
what i mean is.
let's say the FG is configured with 10.10.10.10 as a dns server
vlan 10 dhcp is configured to use the FG interface as DNS so that clients can resolve an internal captive portal. but i want DNS forwarding to use 8.8.8.8 and not 10.10.10.10
hope that makes sense
Simon
What's preventing you from manual setting the DNS servers on the DHCP server settings for the interface?
Edit: Set up a recursive DNS server for the guest network and add a record for the captive portal.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Thanks but already done. The problem is the forwarders. The work around i have at the moment is to configure the guest network public DNS servers as the fortigate DNS servers and all other networks using dhcp to use the company internal dns servers. It works but isn't ideal as this will be pushed out to over 600 boxes and to ensure it can work i need to add a few per location unique source IPs and static routes
Ideally it would be great if you could configure custom dns forwarders on each interface dns service
Simon
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1743 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.