Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mikedelphin
New Contributor

DNS help with firewall and Windows Server 2012 R2!!

Hello! Hope I'm posting this in the right place :)

 

I'm in need of help setting up DNS. I'd like to point out that my knowledge of DNS is not that great as well goes to setting up firewalls. The small company that I work for has a Fortigate 60D firewall that provides DHCP and DNS on it is set to Google's DNS servers (8.8.8.8 & 8.8.4.4). The default gateway is 192.168.10.254.

Now I have a virtual windows server 2012 R2 with a static IP of 192.168.10.12. The GW is 192.168.10.254 and the first DNS is 192.168.10.12. Third DNS is 8.8.8.8. This machine also provides active directory.

Now I did have DNS and DHCP setup on the windows server machine however I disabled those services because every time I had to restart the server for any reason the whole network would go down, so I moved them back to the firewall to handle. Now the issue that I have is that my test windows 10 pro virtual machine that's on the same network can't seem to join the domain. It asks for username and password as per usual but when entered it says "The specified domain either does not exist or could not be contacted." I have tried to put the server's DNS on the machine trying to join the domain.

I have also tried to install the DNS role onto the windows server again but still no dice (see attached pic for DNS server).

2 REPLIES 2
gschmitt
Valued Contributor

mikedelphin wrote:

Now I did have DNS and DHCP setup on the windows server machine however I disabled those services because every time I had to restart the server for any reason the whole network would go down, so I moved them back to the firewall to handle.

Wait... wat?

First things first, reenable DNS and DHCP, set the DHCP's DNS to your server and the secondary to the FortiGate

That way even if you reboot the server a DNS is still reachable

mikedelphin

Hello, thanks for the reply. I'll describe our network better and what I want to achieve: The firewall has 3 vlans 192.168.10.xx & 192.168.20.xx & 192.168.30.xx The firewall's ip is 192.168.10.254 The firewall is handling DHCP and DNS we have a domain controller (windows server 2012) with AD The first vlan (192.168.10.xx) is for staff and the other vlans are for students I want to be able to provide DHCP and DNS to everyone but maintain segregation As well as be able to join computers from all subnets to the same domain The windows server has a DNS server with an entry of 192.168.10.12 (firewall DNS) The server's NIC has both DNS's of 192.168.10.12 and 192.168.20.12

Labels
Top Kudoed Authors