Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ghani
New Contributor

DNS suffix configuration in IPSec phase1-interface

I have a problem that DNS resolution doesn't on my IPsec VPN tunnel. I have seen online that I need to "set domain" in my IPSec phase1-interface configuration. However the command "set domain <domain.xyz>" is not available. I have already enabled mode-cfg. Could you please give me any tips on how can I achieve this? I am using fortogate v6.4. 

1 REPLY 1
sw2090
SuperUser
SuperUser

I had issues with DNS not working in IPSec too. The culprit was that I did set DNS Server(s) and also did set the suffix but the DNS mode was still at auto. Since I did set that up in FortiManager that might have been a bug in FMG.

But also that could mean that you have to set the DNS mode on your p1 to "manual" to make the domain option available...

 

hth

Seastian

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors