Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FantusFiredrake
New Contributor

FortiSASE and Microsoft CDN/FrontDoor DNS

Hi

 

Has anyone managed to solve a problem with FortiSASE (and it's probably the same with Fortigate) where the Fortiguard DNS lookups for the likes of device.autopatch.microsoft.com will return an IP address that matches another service that's hosted in Azure? Which ends up conflicting with policies when you're trying to create explicit ones for MS services and updates, but then random websites get bundled in...?

1 REPLY 1
sjoshi
Staff
Staff

Hi,

 

You mean once you connect SASE VPN you will get DNS from the SASE and the domain device.autopatch.microsoft.com is being resolved to the IP another service that's hosted in Azure.

Can you sent snap of nslookup post connecting and before connecting the SASE VPN for that domain

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors