Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bdubi71
New Contributor II

RDP delay when using FortiClient VPN version 7.2.5 or higher

Hello

 

We have some problems with slow RDP connections when using FortiClient VPN.

 

Let's say we have laptops added to the Active Directory domain called mydomain.com

 

We are using only VPN connections as we are remote workers.

 

We can connect quickly to all severs in the same domain with RDP without any problems.

 

We have also some other Active Directory domains in our infrastructure, called anotherdomain.com and anotherdomain2.com

 

They are in different AD forests and DNS conditional forwarding is configured.

 

The problem is that it is taking approx. 1 minute to connect via RDP to the servers in these different Active Directory domains - this issue only happens if I use FQDN of the server.

 

If I use IP address the connection is immediate, there is no delay.

 

When connected to LAN in the office, no problems, no delays...

 

Interesting part - this problem happens only when using FortiClient VPN version 7.2.5 and higher.

 

When using FortiClient VPN version 7.2.4 I am getting immediate nslookup reply and instant RDP connection:

 

> nslookup server.anotherdomain.com
Server: dc.mydomain.com
Address: 10.x.x.10

Non-authoritative answer:
Name: server.anotherdomain.com
Address: 172.17.2.22


When using FortiClient VPN version 7.2.5 or higher, I get following nslookup reply and RDP connection takes approx. 1 minute

 

> nslookup server.anotherdomain.com
Server: dc.mydomain.com
Address: 10.x.x.10

DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
Non-authoritative answer:
Name: server.anotherdomain.com
Address: 172.17.2.22

 

I created a ticket with Forti support a year ago for this issue and so far the only reply I receive is "I will let you know if I receive any updates from Engineering team" :(

 

Just wondering... Has anyone else seen the problem?

 

#forticlient

 

 

2 REPLIES 2
AEK
SuperUser
SuperUser

Hi

Probably a dns suffix issue.

You may try this:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-add-multiple-dns-suffix-in-SSL-VPN-...

 

Also you may check from FGT side with "siag sniffer" if the DNS request is received and forwarded to the right interface. You may also check if there is no extra suffix added to the requested FQDN, like server.anotherdomain.com.mydomain.com

AEK
AEK
bdubi71
New Contributor II

Thanks for the reply :)

I reconfigured DNS suffixes to include all our suffixes but the problem is still there...

I discovered that we can resolve this problem by disabling DNS Split Tunneling completely in our SSLVPN portal!

This means that in version 7.2.5, Fortinet had to make some changes to the way DNS split tunneling works with their VPN client...

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors