; <<>> DiG 9.8.3-P1 <<>> @208.91.112.53 nctsp.fortiddns.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 45772 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;nctsp.fortiddns.com. IN A ;; AUTHORITY SECTION: fortiddns.com. 765 IN SOA ddns1.fortinet.com. mis.fortinet.com. 2014933327 10800 900 172800 3600 ;; Query time: 234 msec ;; SERVER: 208.91.112.53#53(208.91.112.53) ;; WHEN: Wed Sep 24 21:30:40 2014 ;; MSG SIZE rcvd: 92Hummm ... weird huh ... the primary DNS server doesn' t know this domain, but I noticed that there' s an ddns1.fortinet.com ... so let' s DIG to this one :
; <<>> DiG 9.8.3-P1 <<>> @208.91.114.22 nctsp.fortiddns.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 38371 ;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 0 ;; WARNING: recursion requested but not available ;; QUESTION SECTION: ;nctsp.fortiddns.com. IN A ;; ANSWER SECTION: nctsp.fortiddns.com. 300 IN A 177.139.245.173 ;; AUTHORITY SECTION: fortiddns.com. 86400 IN NS ddns2.fortinet.com. fortiddns.com. 86400 IN NS ddns1.fortinet.com. ;; Query time: 233 msec ;; SERVER: 208.91.114.22#53(208.91.114.22) ;; WHEN: Wed Sep 24 21:31:33 2014 ;; MSG SIZE rcvd: 102Cool, ddns1.fortinet.com knows my IP ... so why primary dns servers are not syncing to the ddns1.fortinet.com ? I was using this ddns for VPN purposes and instantly after I changed the primary DNS server from the fortigate to 208.91.114.22, the VPN connected ... bingo ! and now that the DNS is in cache, I could return the DNS servers to the default ones. This isn' t the first time this happens, has happened other times and on other times, from the remote fortigate, using a ping to nctsp.fortiddns.com just fails saying " the dns could not be resolved" It would be nice if someone just check those 2 DNS Fortinet DNS servers.
Luiz Alberto Camilo NCT São Paulo www.nct.com.br NSE-5 Expert
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Dr. Carl Windsor Field Chief Technology Officer Fortinet
Luiz Alberto Camilo NCT São Paulo www.nct.com.br NSE-5 Expert
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.