Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortiauthenticator and DNS suffix / shortnames
Hi,
Have an authenticator and single fortigate, radius accounting / single signon, etc all work fine.
We have a big problem with FSSO sessions where the authenticator is only informing fortigate the identity of a small portion of connections. Troubleshooting the problem shows that authenticator cannot resolve shortnames through dns.
The domain name is configured correctly in authenticator, the authenticator is part of the domain, can resolve if the fqdn is used for the local dns server (windows dns) responds with a ' bad request' when attempting to resolve a shortname.
Any assistance appreciated as FSSO is not usable until we can get this working
Mark
Infosec Partners
Infosec Partners
4 REPLIES 4
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What are your DNS settings and have you set the hostname/DNS domain name setting in the system information widget?
Dr. Carl Windsor
Chief Information Security Officer (CISO)
Fortinet
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DNS servers point to primary and secondary windows dns servers in the domain, hostname set to default, domain name have tried FQDN and domain name in the dash widget.
Infosec Partners
Infosec Partners
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This appears to be due to the search domain not being configured in the DNS lookup. I notice you already have a support ticket open on this. I will get the support team to report back on this in due course.
Dr. Carl Windsor
Chief Information Security Officer (CISO)
Fortinet
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, trying to find where / how to change this - there is a ticket, thanks for the response
Mark
Infosec Partners
Infosec Partners
