Hi,
I have this scenario:
Company network, FortiGate as a NGFW.
config system dns point to internal Active Directory DNS servers.
There is a visitor network for which I would like to use FortiGate as a DNS server in DHCP offer.
With appropriate firewall policies I am able to block access from visitor network to internal networks.
But I would want visitors not to be able to translate internal hostnames and addresses as well.
Is there a way to achieve this?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello
Just create a few VLANs for each network
You should just point your visitors DNS to your ISP's DNS (or any DNS really, who cares). There is no way to block them from resolving IP addresses if you let them access your DNS and if there is any DNS vulnerability then it is a possible attack vector from one system to another.
Dont forget if the port is open to your domain DNS then they can still use NSLOOKUP to resolve internal names so you should not even have any ports open to your internal network including DNS.
to be able to resolve internal hostnames you would have to configure the DHCP Serve ron that interface to offer the system dns servers (as you wrote they are set to your internal AD DNS).
That may also mean that you will have to allow clients in your visitor network to access your AD DNS with Service DNS (53/UDP).
The less elegant way would be to create a dns db on the FGT and enter all the internal hostnames there. Then create a recursive DNS Forwarder on the visitor net interface which uses some external DNS as forwarder. Then set the DHCP to offer the interface ip als DNS.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.