Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

Fortigate as SSL VPN Client

When i configure my fortigate lab as ssl vpn client to connect to the fortigate at office, why when ssl vpn connected then internal network under fortigate lab is not reachable to connect to the intenret by hostname? Actualy fortigate on the lab act as dns server also.

Traffic from lab to the internet is working fine, i can ping by ip (8.8.8.8) but the issue i can't ping by hostname.

5 REPLIES 5
AEK
SuperUser
SuperUser

So it is a DNS issue.

I guess you already checked this guide.

https://docs.fortinet.com/document/fortigate/7.4.2/administration-guide/508779/fortigate-as-ssl-vpn-...

Is your FGT LAB the DNS server for your internal network?

Can FGT LAB ping hostnames when connected to VPN?

Does the DNS server of the FGT LAB change when connected to VPN?

AEK
AEK
HS08
Contributor

I have internal network in the lab and dns server in the FGT Lab is for lab network only.

The FGT itself can't ping using  hostname when ssl vpn connected.

When FGT LAB connected to the ssl vpn the ip of dns server in not change.

AEK

Try check how dns request is routed once connected to VPN. Probably it is sent through the tunnel.

AEK
AEK
HS08
Contributor

Yes, dns request redirected to the tunnel. How we can disable this?

AEK

You may check the routing. When you connect to VPN the routing table of your FGT is probably altered in such way to reroute the DNS queries to the remote FGT via the tunnel.

If this is the case then you need to review the VPN routing config.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors