Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
thoph
New Contributor

FSSO DCagent pick wrong record DNS when clients change network

Hi everyone,

Our system uses Collector and DCagent for authentication.

My problem is when clients change networks (for example, from wired to Wi-Fi or to a different subnet), they lose their authentication.

The root cause is that, as I investigated, after changing the network, DHCP could not request to delete the PTR record from the old subnet, so sometimes DCagent still picked those old records for the IP/hostname sent to the collector, and it took a long time to get the right DNS record.

As I know, DHCP servers do not perform request updates/deletes for the reverse zone to delete old PTR records because the new IP is in a new zone subnet, and they keep the old PTR record until scavenging does the work.

How to fix this problem? Are there any options to prevent DCagent from picking the PTR record? 

 

1 REPLY 1
funkylicious
SuperUser
SuperUser

"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors