Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rharms_tarc
New Contributor III

IPsec Dynamic DNS Addresses Not Updating

I have around 180 IPsec tunnels established using Dynamic DNS for the remote gateway.  The local end is a FortiGate 300E running v7.4.7 build2731.  The remote ends are Digi cellular routers installed on our fleet of transit buses.  As they are located on buses, obviously the tunnels are not up and running all the time, just when the bus is in operation.  At times, the FortiGate seems to miss a Dynamic DNS update which will cause that tunnel not to come up.  In most cases, the record from our DNS provider updates correctly to reflect the buses' new public IP address.  But for whatever reason, the FortiGate continues to try to connect to the old IP address.  If I go into the FortiGate and force it to do a DNS query for the tunnel (generally by changing the Dynamic DNS entry to a different DNS entry and then changing it back to the correct one), the FortiGate will update the address and the tunnel will come right up.

 

So I'm wondering if there is a way to make the FortiGate do those DNS queries more frequently or more dependably so that they will pick up the Dynamic DNS updates from our DNS provider?

0 REPLIES 0
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors