Hello I have an issue with a fortigate 30D thats located at a remote office.
Situation:
one fortigate 60D at HQ with internet con1
one fotigate 30D with internet con2
VPN connection between the two offices
DNS server is at HQ
Problem: each time the internet gets disconnected at HQ, branch office also lose connection. My bet is because there is no DNS server at Branch to revolve addresses so branch cannot browse.
grateful if anyone can help in resolving this issue.
hi,
depends on the branch config:
- what is specified for 'system DNS'?
- where does the route to the system DNS point to - the local internet breakout, or the remote LAN behind the tunnel?
- how is the remote gateway for the VPN identified - via FQDN or IP address?
Hi ede_pfau, thanks for your quick response. to answer your questions:
- what is specified for 'system DNS? DNS on fortigate 30D are Primary(HQ DNS server) Secondary(public google DNS)
- Where does the route to the system DNS point to - the local internet breakout, or the remote LAN behind the tunnel? Primary(HQ DNS server) Secondary(public google DNS)
- how is the remote gateway for the VPN identified - via FQDN or IP address? via IP address
I would use diag debug flow for the GOOG DNS and see if you have a 1> firewall policy 2> and ensure the route is active during the outage at the HQ. Sounds like your firewall policy might be missing or some other issues
# a quick check is to scan thru the cfg
#
show full | grep -f 8.8.x.x
PCNSE
NSE
StrongSwan
GM, I have a firewall policy that allow connection to the internet
Name: Lan to INternet
INcoming Interface my interface for the lan
outgoing interface my interface where SP is
Source All
destination All
Schedule Always
Service All
Action Accept
This policy is enabled and is at the top of the order.
following this policy is my VPN policy that allows connection from HQ to Branch
Please note i am only learning to use the fortigate UTM so all these configuration is new to me. Appreciate your help.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.