Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
freaky
New Contributor

Dual WAN, DNS issues

Hey there, having some problems with a dual WAN setup. Both lines are from a different ISP. The problem is DNS is functioning flaking. This isn' t that weird, but I don' t know how to solve it exactly. The Fortigate needs DNS servers for several things. Amongst other things from the spam check (check the MX records), synchronizing the time (if you used URL instead of IP) and several other things. Most ISP' s only let you resolve if you' re one of their members. For all others they only resolve what they are responsible for. The problem is I don' t know how Fortigate decides what DNS server to approach over which connection and it won' t connect to the internal server. Next to that it' s my understanding that policy routing doesn' t work on traffic originating from the fortigate itself and it' s also important that the line is redundant. So what I did now is just enter 2 DNS servers. The primary ones from both ISPs, but it' s flakely at best. Using nslookup I sometimes have to try to resolve it up to 5 times for it work. Browser mostly has even more problems as it appearantly doesn' t try to look-up again if it failed (or failed a couple of times in a row). Any suggestions? Tried entering our DNS server in the LAN, but appearantly it doesn' t want to use that, as DNS on the Fortigate stopped completely at that point. It would be nice if I could force the fortigate out of a line for a specific dns server (perhaps add static routes for the IP addresses of the DNS server?!). If the fortigate always uses the first (or the second) line, I could enter only the dns servers from that ISP, _but_ that will break redundancy...
2 REPLIES 2
Not applicable

Same problem I' m facing also. After installed another diff ISP wan link, my MS Outlook' s email cannot send out using smtp server, plus I received all incoming mail with " spam" in very email' s subject. ... Now I' m stuck...very stuck...
freaky
New Contributor

My problem is just with the Fortigate. Probably I can help you with your problem. If you use Exchange and the fortigate load balances (so outgoing mail could go through either wan1 or wan2 (not fixed to specific port)) remove any smart hosts, so exchange itself is responsible for delivery. You see if exchange would go out via ISP2 but uses the SMTP server of ISP1 as smart host, that server will reject the mail (as they won' t relay for other ISPs). if you use only outlook and load balance you' re essentially screwed... you would have to fix outgoing smtp traffic to the wan interface on the ISP you use for sending the e-mail. Concerning incoming e-mails, this is very strange. You don' t happen to have 2 profiles, one which rejects/discards the mail and another who tags it do you?
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors