I want to set the DNS on my fortigate to the interal DNS in a second site. But although I have a working IPSEC VPN tunnel the fortigate itself is unable to access the remote subnet. How can I resolve this issue?
Open a policy on the remote tunnel that allows the interface IP into the DNS server. The FGT comes across with that IP, not the LAN on that unit.
HTH
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Yeah, sounds like a policy issue (if the tunnel is actually building properly)
Mike Pruett
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.