Hello FortiCommunity,
We currently are using FortiClient with an EMS server and noticed when we connect to the VPN we received our specified internal DNS on both our physical adapter (wifi/lan) and our vpn adapter. Our specified internal DNS are our domain controllers that run DNS services.
The issue we are having with this is that sometimes the FortiClient software disconnects or something in windows causes the application to crash. My assumption is when you hit the disconnect button on the FortiClient it removes routes and/or the static DNS entry. With that process not taking place the end result is that the static DNS that was not cleared, thus leaving the PC unable to connect to the internet.
Our users working from home do not get admin access to their network adapters as well. The combination leaves the end user unable to connect to the internet and our remote tool useless. Do you guys know why the static DNS is set- can we set this to obtain automatically? I did try "same as client system DNS" but our firewall uses the FortiNet's DNS for what I can only assume is DNS filtering along with other items.
Is there a way to stop these crashes or disconnects? Has anyone else had this issue?
Thanks,
Michael
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
We are on version 6.4.3 for most of our endpoints. After upgrading to version 7.0.6 via deployment on the EMS server- this seemed to fix the issue. Regardless if a user switches wifi networks or if the network gets dropped the static DNS entries get removed successfully now.
@JEG19ONine wrote:I've been struggling with one user for a month, finally found that his DNS were all set to static for the wifi NIC. Difficult to fix because A) users don't have admin rights, B) bad DNS means no internet, means no remote tools. Finally got him working, and employee 2 says "I heard your fixed 1s problem. I have the same issue." So I start digging deeper and 5 minutes into research I find the FortiClient/DNS issue. Very frustrating that it appears to have existed for years too!
I got this,...
As in the past for me, the problem seems to disappear on its own. My company would have updated to a new release when available, so it's possible that 7.2.1 fixed it for us.
Don't update to 7.2.2 if you can avoid it. Nothing but problems with that version. Probably should have rolled back our deployment, but we're hanging on with it for now.
We are on version 6.4.3 for most of our endpoints. After upgrading to version 7.0.6 via deployment on the EMS server- this seemed to fix the issue. Regardless if a user switches wifi networks or if the network gets dropped the static DNS entries get removed successfully now.
We are on 7.0.9 and the issue is still present.
We still have this problem on 7.0.7 and are now considering other solutions. We've had this problem since we first got this product.
We have the same problem with forticlient 7.2.3 not on all clients but on a few. I think this problem could be related with windows..
does Fortinet doing something with the matter? Is the free version involved to promote paid version?
any fortinet engineer can take a word?
On our side, we are using FortiClient 7.0.11. We started to roll out Windows 11 23H2 last month and some customers experienced the same issue right after the upgrade. We created a script that runs locally to remove the DNS entries since the computer is not reachable via internet. This issue never happened in Windows 10. Right now, I'm stuck between Microsoft saying it's not their issue and Fortinet saying they fixed this issue a long time ago.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.