We used to have FortiClient version 6.2.6 and it works well on SSL VPN connection to our corporate network (gateway FortiOS version 6.4.3). Once we upgraded to FortiClient 6.4.3, we start getting intermittent connectivity issue in that user cannot access network resources due to DNS resolution failure. It's found to be caused by client's network interface attempts to query DNS through IPv6 and failed. It then stop there without attempting querying IPv4 DNS. We are stuck with no solution from Fortigate and desperately need to resolve it. Does anyone encounter similar issue and can share some ideas?
Thanks
Solved! Go to Solution.
So far we have not encountered any issues with IPv6 enabled home users, however it was only a small percentage of our users that have IPv6 enabled Internet connections so can't say for 100% certainty yet.
FortiClient is independent of the Fortigate firmware version so yes you need EMS 7.0 or later and you may need to convert your EMS licences to version 6.4 at least then other than that you can upgrade your clients to 7.0 so not a lot of work at all.
I was encountering the same type of issues. Like 90% of all issues, it came from DNS resolution who was made in IPv6 prior to IPv4. As we don't use IPv6 internally, clients with IPv6 enabled internet connections where unable to resolve internal names, because they were querying their Internet provider instead of the one pushed through the VPN connection.
Workarounds are:
or
- Disable IPv6 on the Client interface connecting to Internet or generally
or
- having a full dual stack infrastructure.
I wonder if there isn't already a solution mixing IPv6 DNS-Database , "private" IPv6 and 6to4....
Cheers
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.