When i configure my fortigate lab as ssl vpn client to connect to the fortigate at office, why when ssl vpn connected then internal network under fortigate lab is not reachable to connect to the intenret by hostname? Actualy fortigate on the lab act as dns server also.
Traffic from lab to the internet is working fine, i can ping by ip (8.8.8.8) but the issue i can't ping by hostname.
So it is a DNS issue.
I guess you already checked this guide.
Is your FGT LAB the DNS server for your internal network?
Can FGT LAB ping hostnames when connected to VPN?
Does the DNS server of the FGT LAB change when connected to VPN?
I have internal network in the lab and dns server in the FGT Lab is for lab network only.
The FGT itself can't ping using hostname when ssl vpn connected.
When FGT LAB connected to the ssl vpn the ip of dns server in not change.
Try check how dns request is routed once connected to VPN. Probably it is sent through the tunnel.
Yes, dns request redirected to the tunnel. How we can disable this?
You may check the routing. When you connect to VPN the routing table of your FGT is probably altered in such way to reroute the DNS queries to the remote FGT via the tunnel.
If this is the case then you need to review the VPN routing config.
User | Count |
---|---|
2522 | |
1347 | |
794 | |
639 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.