Hi
I'm running FortiOS v7.2.0,build1157,220331 on FortiGate-200E
I enabled DNS Database in Feature Visibility and configured it like this:
config system dns
set primary 1.1.1.1
set secondary 1.0.0.1
set protocol cleartext dot doh
set server-hostname "one.one.one.one"
set domain "test.local"
end
config system dns-server
edit "port3"
set mode forward-only
next
end
config system dns-database
edit "Test"
set domain "test.local"
set view public
set authoritative enable
config dns-entry
edit 1
set hostname "@"
set ip 192.168.5.15
next
edit 2
set hostname "asd"
set ip 192.168.5.15
next
end
set primary-name "dns1"
set contact "host@test.local"
next
end
(The IP Address of port3 is 192.168.5.1)
The firewall doesn't respond to DNS for this domain and forwards the request to other DNS servers instead of resolving it from the local database
I tried dig for these domains and all of them failed to resolve:
How can I fix this?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Your DNS server seems to be set to forward-only, which will only forward to the public DNS configured, without checking the local database.
Ok, I set the view to shadow (in addition to DNS server mod), and it works now.
But I can't understand what does internal and public users mean
Zone view (public to serve public clients, shadow to serve internal clients).
shadow: Shadow DNS zone to serve internal clients.
public: Public DNS zone to serve public clients.
Your DNS server seems to be set to forward-only, which will only forward to the public DNS configured, without checking the local database.
Thanks for your reply
It works in non-recursive mode but doesn't work in recursive mode.
Ok, I set the view to shadow (in addition to DNS server mod), and it works now.
But I can't understand what does internal and public users mean
Zone view (public to serve public clients, shadow to serve internal clients).
shadow: Shadow DNS zone to serve internal clients.
public: Public DNS zone to serve public clients.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.