Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
YHC
New Contributor III

DNS of SSL-VPN

Dears,

 

I recently configure SSL-VPN on my Fortigate 40F.

The connection is successful in my iPhone.

Howevver, I found that I can only connect to our internal NAS/server using its private IP, like 192.168.3.x.

I have set the A record of our NAS/server with their private IP but it not works.

 

Can you advise what should I do to connect to our internal NAS/server with its FQDN?

Thank you.

6 REPLIES 6
funkylicious
SuperUser
SuperUser

---------------------------geek---------------------------
YHC
New Contributor III

Hi I tried the second approach but the CLI said:

 

command parse error before 'dns-server1'
Command fail. Return code -61

 

It seems the command changed?

funkylicious

Where/when does the error pop? The article saying under the ssl web portal, i dont know if its still works like that, i always do it under the ssl settings.

You should configure the dns server under sslvpn settings alonsgide the dns-suffix in order to resolve the shortname.

 

config vpn ssl settings
    set dns-server1 <>
end
---------------------------
geek
---------------------------
---------------------------geek---------------------------
YHC
New Contributor III

Hi funkylicious

 

I have settings in the GUI like this:

Please advise me if I have missed any setting.  Thank you.

截圖 2024-10-21 07.16.55.png截圖 2024-10-21 07.17.16.png

funkylicious

Hi,
Those settings are relevant for the device.

The ones that you need are configured in the CLI, config vpn ssl settings.

---------------------------
geek
---------------------------
---------------------------geek---------------------------
adimailig
Staff
Staff

Dear @YHC 

If you could connect to the fully qualified domain (hostname.fully_qualified_domain.local), then your issue is with the DNS suffix.
Please add DNS Suffix on your SSL VPN configuration.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-set-DNS-suffix-for-VPN-SSL-and-IPse...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-DNS-Suffix-per-SSL-VPN-Portal/ta-p/277180


Best Regards,

Arnold Dimailig
TAC Engineer
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors