Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
chipcoit
New Contributor II

FortiClient & Static DNS Entry

Hello FortiCommunity,

We currently are using FortiClient with an EMS server and noticed when we connect to the VPN we received our specified internal DNS on both our physical adapter (wifi/lan) and our vpn adapter. Our specified internal DNS are our domain controllers that run DNS services.

 

The issue we are having with this is that sometimes the FortiClient software disconnects or something in windows causes the application to crash. My assumption is when you hit the disconnect button on the FortiClient it removes routes and/or the static DNS entry. With that process not taking place the end result is that the static DNS that was not cleared, thus leaving the PC unable to connect to the internet. 

 

Our users working from home do not get admin access to their network adapters as well. The combination leaves the end user unable to connect to the internet and our remote tool useless. Do you guys know why the static DNS is set- can we set this to obtain automatically? I did try "same as client system DNS" but our firewall uses the FortiNet's DNS for what I can only assume is DNS filtering along with other items. 

 

Is there a way to stop these crashes or disconnects? Has anyone else had this issue?

 

Thanks,
Michael

1 Solution
chipcoit
New Contributor II

We are on version 6.4.3 for most of our endpoints. After upgrading to version 7.0.6 via deployment on the EMS server- this seemed to fix the issue. Regardless if a user switches wifi networks or if the network gets dropped the static DNS entries get removed successfully now.

View solution in original post

20 REPLIES 20
antech
New Contributor

Unfortunate that this is still an ongoing issue years later. We are seeing this issue on v 7.4.3 (latest build) as well.

This is a major issue for Hybrid users who work from home on occasion. When disconnecting from the VPN, the Wi-Fi adapter remains set to a "static" DNS server (which gets set to the user's home router/DNS server after disconnecting from the VPN).

When the users come into the office, they cannot connect to the Wi-Fi because their DNS server is still locked to 'static', and they cannot change it because it requires elevation. The 'fix' is to have them connect wired (not all buildings have a wired connection) so that an IT admin can remote in and enter their admin credentials to reset the DNS to Automatic (DHCP).

After setting it back to Automatic, if the user works remotely again & connects to the VPN, it again gets set back to Manual. :(

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors