Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BernhardM
New Contributor

FGT 60C as Backup DNS-Server

HI! we have a FGT 60C and a Windows 2003 DC with DNS. Is it possible to use the FGT as Backup DNS-Server (slave mode?). So if the Windows Server is down, the Clients should be able to resolve DNS-Queries over the FGT - inclusive some internal IPs p.ex. Webservers. I have activated the DNS-GUI, created a non autorative shadow slave. on the Windows Server I' ve added the FGT IP for zone transfer for reverse and forward zone. any ideas? br Bernhard
FGT 60C
FGT 60C
2 REPLIES 2
ede_pfau
Esteemed Contributor III

One problem with a secondary DNS is that the clients wait a long time before querying the secondary if the primary is down (~ 20 sec). Browsing (with many URL lookups) is a pain then. If you are willing to manually ' switch over' the FGT can help you: - create a VIP on the internal interface with an unused local IP address - activate the mapping in a ' internal->internal' firewall policy - map to your primary DNS - put the VIP into your DHCP configuration as DNS Your clients will query the virtual IP now, not the real server' s IP. If you schedule a server downtime, change the VIP ' mapped-to' IP to the Fortigate' s internal interface IP. Of course, the FGT' s DNS must query recursively, i.e. names it doesn' t know must be forwarded to your ISP.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
FortiRack_Eric
New Contributor III

Bear in mind that FortiOS split DNS function only works for A and MX records, it doesn' t handle SRV and TXT records so your windows clients cannot find a DC.

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Labels
Top Kudoed Authors