Since we migrated to Fortinet and SSL-VPN with FortiClient last year, we have had an increasing number of issues with the client leaving DNS registration disabled on wired and wireless interfaces after a user disconnects from VPN.
The "no_dns_registration" option is set to 2 in the configuration, and it successfully disables registration for the local adapter(s) while connected and restores the setting after disconnecting the majority of the time. However, we find at least one user weekly whose computer still has a VPN IP address in AD DNS even though they are in the office. FortiClient version is 7.4.3 (VPN only). The Advanced TCP/IP Settings window on their network adapter shows that DNS registration is disabled:
I thought it may be related to users closing their laptops while connected to VPN or otherwise not disconnecting cleanly, but thus far I have been unable to reproduce it on demand.
Is anyone else experiencing this and do you have any suggestions for resolving it? I'm working a script to clean up the settings periodically, but I am hoping for a less clunky solution.
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Thanks,
Hi,
If FortiClient SSL VPN fails to restore DNS registration settings after disconnecting, follow these steps to troubleshoot and resolve the issue:
User | Count |
---|---|
2640 | |
1400 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.