Hello,
We have a interesting Setup. We have the normal starlink setup + we have a managed router which our provider is using to provide us with a static IP address. They have a ipsec tunnel to our Fortigate and then we have a ipsec site to site vpn back to them. The tunnel itself comes up fine but then nothing can resolve cant go to yahoo.com cnn.com but it has internet access you can ping 8.8.8.8 and access most internal sites.
Has anyone seen this issue before and have any recommendations?
Hi theo102,
The fact that you can ping 8.8.8.8 but can't reach yahoo.com indicates that DNS is not resolving domain names properly.
Please review your firewall policy to see which services are allowed, and try pinging google.com to verify connectivity.
Take the debug flow filter logs and share us the output
https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/54688/debugging-the-packet-flow
Regards,
Aman
This only happens when we plug Starlink in. Our old ISP on this same SD-WAN member does not have this problem. It seems to be something related to us using a static ip carrier with a managed router and Starlink?
Hi,
Are you accessing internet via the direct ISP or via the VPN tunnel.
Share below output:-
get router info routing-table all
What is the DNS you have setup on the FGT
Network> DNS
share snap
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.