Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Roy690916
New Contributor II

FortiClient vpn dns suffix issue

hi

My FortiGate 200F , OS version : 7.0.16

setting use ssl vpn and dns suffix (my environment have mutiliple domain)

config vpn ssl settings

     set dns-suffix “test1.com; test2.co.uk; test3.net”

  end

my internal web  =>  https://www1.test1.com  

 

apple iphone  forticlient vpn  After connecting   can connect  https://www1.test1.com  => OK 

input hostname   www1 => OK

but  android forticlient vpn  version 7.4.1.0176  , not working  

only input  Complete FQDN https://www1.test1.com  OK  , hostname  not OK 

 

What is the reason for this?

 

2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Roy

This should have something to do with the search list in client's DNS config

When search list is properly configured, when you try reach a hostname without FQDN, the DNS client adds the "search" domain to the hostname, then sends the DNS request.

It seems for some reason on your Android device the search domain is not set (or not set properly) when you connect with VPN.

There should be a method or some tool to check the search domain on Android.

AEK
AEK
kaman
Staff
Staff

Hi Roy690916,

You can check with the different Anroid and FortiClient version 7.2.x.

Please collect the SSL VPN logs and check both working and non-working logs

Also, please refer to the below document for more information:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-User-DNS-Suffix-Configuration-Caus...

Regards,
Aman

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors