Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
chipcoit
New Contributor II

FortiClient & Static DNS Entry

Hello FortiCommunity,

We currently are using FortiClient with an EMS server and noticed when we connect to the VPN we received our specified internal DNS on both our physical adapter (wifi/lan) and our vpn adapter. Our specified internal DNS are our domain controllers that run DNS services.

 

The issue we are having with this is that sometimes the FortiClient software disconnects or something in windows causes the application to crash. My assumption is when you hit the disconnect button on the FortiClient it removes routes and/or the static DNS entry. With that process not taking place the end result is that the static DNS that was not cleared, thus leaving the PC unable to connect to the internet. 

 

Our users working from home do not get admin access to their network adapters as well. The combination leaves the end user unable to connect to the internet and our remote tool useless. Do you guys know why the static DNS is set- can we set this to obtain automatically? I did try "same as client system DNS" but our firewall uses the FortiNet's DNS for what I can only assume is DNS filtering along with other items. 

 

Is there a way to stop these crashes or disconnects? Has anyone else had this issue?

 

Thanks,
Michael

1 Solution
chipcoit
New Contributor II

We are on version 6.4.3 for most of our endpoints. After upgrading to version 7.0.6 via deployment on the EMS server- this seemed to fix the issue. Regardless if a user switches wifi networks or if the network gets dropped the static DNS entries get removed successfully now.

View solution in original post

17 REPLIES 17
raptert


@JEG19ONine wrote:

I've been struggling with one user for a month, finally found that his DNS were all set to static for the wifi NIC. Difficult to fix because A) users don't have admin rights, B) bad DNS means no internet, means no remote tools. Finally got him working, and employee 2 says "I heard your fixed 1s problem. I have the same issue." So I start digging deeper and 5 minutes into research I find the FortiClient/DNS issue. Very frustrating that it appears to have existed for years too!


I got this,...

https://xender.vip/
tschulten

As in the past for me, the problem seems to disappear on its own. My company would have updated to a new release when available, so it's possible that 7.2.1 fixed it for us.

 

Don't update to 7.2.2 if you can avoid it. Nothing but problems with that version. Probably should have rolled back our deployment, but we're hanging on with it for now.

chipcoit
New Contributor II

We are on version 6.4.3 for most of our endpoints. After upgrading to version 7.0.6 via deployment on the EMS server- this seemed to fix the issue. Regardless if a user switches wifi networks or if the network gets dropped the static DNS entries get removed successfully now.

SubaruEurope

We are on 7.0.9 and the issue is still present.

OffroadingConvoy4
New Contributor

We still have this problem on 7.0.7 and are now considering other solutions. We've had this problem since we first got this product.

matthew_wlf

We have the same problem with forticlient 7.2.3 not on all clients but on a few. I think this problem could be related with windows..

lkosc
New Contributor

does Fortinet doing something with the matter? Is the free version involved to promote paid version? 

any fortinet engineer can take a word? 

PierrePaulDuval

On our side, we are using FortiClient 7.0.11. We started to roll out Windows 11 23H2 last month and some customers experienced the same issue right after the upgrade. We created a script that runs locally to remove the DNS entries since the computer is not reachable via internet.  This issue never happened in Windows 10. Right now, I'm stuck between Microsoft saying it's not their issue and Fortinet saying they fixed this issue a long time ago.  

Pierre-Paul Duval
Pierre-Paul Duval
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors