Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
I ended up hacking the problem another way.
I created a "common" network that all VPN clients have access to, and placed a DNS server on that network, setting all VPN clients to use that DNS server while connected. The DNS server knows about the domains that individual clients will request, and forwards requests to servers on the appropriate client network. The firewall has ACLs to permit the DNS server to query the client networks DNS servers.
Downside to this solution is I can't push a dns suffix to clients, but other than that it works properly.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.