Hello, I am using FortiGate version 7.2.10. I am distributing DHCP via the FortiGate interface over VLAN. The lease time is set to 7 days, but when the lease expires, PTR records on the DNS are deleted. There are DNS-update commands available in the DHCP server CLI, but it seems like those commands are not working, as it doesn't allow me to run them. How can I dynamically resolve this issue and make it permanent so that PTR records are not deleted? Best regards.
Hi B_B
Can you explain which PTR is deleted, on which DNS server and give a screenshot if possible?
Hello, in Active Directory, it is being deleted from PTR. Actually, the issue I'm experiencing is mentioned in the link https://community.fortinet.com/t5/Support-Forum/Does-Forti-actually-update-DNS-from-DHCP/td-p/9607, and it even says that I won't be able to fix this issue in previous versions. However, is this issue present in this version?
sss
Does it resolve the issue if you configure a DHCP relay on FG interface to forward to your AD?
Hi, thank you for your interest. However, I think I was misunderstood. I don't want to use relay, I want to create a DHCP pool on the FW interface. I have already done that, but my actual problem is this: when I create a DHCP pool on the FW interface, I am facing the issue where the PTR (reverse DNS) records of the IP addresses coming from that block are missing on the DNS.
I understand the issue but I don't know a solution that can be implemented on FG side. However I actually I always see companies using AD DHCP server (instead of FG's) for the corporate clients, and I know they don't have such issue when they do so.
I understand. In the Fortigate architecture, opening DHCP pools on VLANs on the interface is actually not a recommended setup. They should create this scope on the DHCP server instead. Do you have any resources regarding this, such as a Fortinet document?
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.