Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DaveRattenbury
New Contributor

Issue between Fortigate Firewall DHCP and Windows DNS

Hi All,

So have a strange problem. We recently started testing Entra Only computers (we use hybrid AD computers currently)

In our old setup

Computers connected to LAN - IP address updated in DNS

Computers connected via SSL VPN (Forigate) - IP address updated in DNS

In Our new setup

Computers connected to LAN - IP address updated in DNS

Computers connected via SSL VPN (Forigate) - IP address NOT updated in DNS

I cannot work out why. I have checked the following.

DNS will accept dynamic updates

The fortigate SSL network adapter is set to register with DNS and the correct servers.

Any ideas what else could be causing this? As we move forward with the roll out of Entra / Azure AD computers this will become more of a problem.

Thanks

5 REPLIES 5
alicejeans
New Contributor


@DaveRattenburybotox dubai wrote:

Hi All,

So have a strange problem. We recently started testing Entra Only computers (we use hybrid AD computers currently)

In our old setup

Computers connected to LAN - IP address updated in DNS

Computers connected via SSL VPN (Forigate) - IP address updated in DNS

In Our new setup

Computers connected to LAN - IP address updated in DNS

Computers connected via SSL VPN (Forigate) - IP address NOT updated in DNS

I cannot work out why. I have checked the following.

DNS will accept dynamic updates

The fortigate SSL network adapter is set to register with DNS and the correct servers.

Any ideas what else could be causing this? As we move forward with the roll out of Entra / Azure AD computers this will become more of a problem.

Thanks


It sounds like the issue might be with DNS updates for VPN clients. Here are a few things to check:

  1. VPN Adapter Configuration: Ensure the FortiGate VPN adapter is configured to register DNS updates correctly.

  2. DNS Registration Settings: Verify that the VPN clients are configured to update DNS records. Sometimes, specific settings or policies might prevent updates from being sent.

  3. Network Configuration: Check if there are any specific firewall rules or network settings on the FortiGate that might be blocking or interfering with DNS update requests.

  4. DNS Server Logs: Review DNS server logs to see if there are any errors or blocked update attempts.

Addressing these points should help resolve the issue with DNS updates for VPN clients.

DaveRattenbury

Hi @alicejeans 

 

Thanks for your reply.

VPN Adapter Configuration: Ensure the FortiGate VPN adapter is configured to register DNS updates correctly. - It is

 

DNS Registration Settings: Verify that the VPN clients are configured to update DNS records. Sometimes, specific settings or policies might prevent updates from being sent.

I can't see any policy on any of these Entra PC's

 

Network Configuration: Check if there are any specific firewall rules or network settings on the FortiGate that might be blocking or interfering with DNS update requests.

This is the only area I am not sure on. Though to be fair we cannot see anything blocked on the forti analyzer.

 

DNS Server Logs: Review DNS server logs to see if there are any errors or blocked update attempts.

Cannot see anything on the DNS server to indicate any problems. 

 

As I said in my original post it works absolutely fine for Hybrid devices (on-prem AD) but not for Azure only devices.

hbac

Hi @DaveRattenbury,

 

Please check the firewall policy on FortiGate and make sure there is no inspection for traffic from SSLVPN clients to the DNS server. I assume SSLVPN client computers are domain joined with Azure AD? You can also take packet captures for more information. Please refer to this article: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Packet-Capture-on-FortiOS-GUI/ta-p/1...

 

Regards, 

DaveRattenbury

Hi @hbac 

 

The computers that have the issue are Not domain joined. They are only joined to Entra /Azure AD.

 

Will that not work?

Dave

cc92
New Contributor

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors