Hi guys,
Need some help figuring out this DNS issue.
Scenario:
1) on prem fortigate is connected to AWS via ipsec tunnel.
2) on prem windows based DNS server is configured on fortigate and everything is working fine
3) using SSL vpn for remote users to connect to network
4) able to reach on prem and AWS resources
5) NOT able to resolve AWS DNS names when connected via SSL VPN (split tunnel)
6) nslookup is able to resolve the web address and show correct on prem DNS server
7) Still not able to access the website, curl command also shows no result
if anyone has a suggestion as to why this is happening i would greatly appreciate that. thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi
If I understand well your issue, I think the fastest way to fix this is to add AWS DNS as secondary DNS in your SSL VPN settings.
hi, i tried that already. it doesn't work. i added the AWS DNS to port DNA settings.
Have added a firewall policy to allow this DNS traffic from VPN clients to AWS?
You may also need to add a route back on AWS to reach you VPN clients.
After that disconnect the client the connect again, the try nslookup from client to send DNS query from client to AWS.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1105 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.