Hi everyone,
Our system uses Collector and DCagent for authentication.
My problem is when clients change networks (for example, from wired to Wi-Fi or to a different subnet), they lose their authentication.
The root cause is that, as I investigated, after changing the network, DHCP could not request to delete the PTR record from the old subnet, so sometimes DCagent still picked those old records for the IP/hostname sent to the collector, and it took a long time to get the right DNS record.
As I know, DHCP servers do not perform request updates/deletes for the reverse zone to delete old PTR records because the new IP is in a new zone subnet, and they keep the old PTR record until scavenging does the work.
How to fix this problem? Are there any options to prevent DCagent from picking the PTR record?
hi,
maybe https://community.fortinet.com/t5/FortiGate/Technical-Tip-Disable-the-DNS-resolution-of-the-FSSO-DCA... will help
| User | Count |
|---|---|
| 2829 | |
| 1433 | |
| 812 | |
| 789 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.