One problem with a secondary DNS is that the clients wait a long time before querying the secondary if the primary is down (~ 20 sec). Browsing (with many URL lookups) is a pain then.
If you are willing to manually ' switch over' the FGT can help you:
- create a VIP on the internal interface with an unused local IP address
- activate the mapping in a ' internal->internal' firewall policy
- map to your primary DNS
- put the VIP into your DHCP configuration as DNS
Your clients will query the virtual IP now, not the real server' s IP.
If you schedule a server downtime, change the VIP ' mapped-to' IP to the Fortigate' s internal interface IP.
Of course, the FGT' s DNS must query recursively, i.e. names it doesn' t know must be forwarded to your ISP.
Ede
"Kernel panic: Aiee, killing interrupt handler!"