- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN IPSec - DNS
I've set up an IPSenc VPN between a head office and a branch office, two F60 fortigates, but we can't access the head office network folders, when I put DNS on the network card it works perfectly, without DNS on the card I can ping and everything, is there anything I can do so that I don't have to put DNS on the network card?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need to enable split DNS, available only for IKEv2 on the later FOS versions.
https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/836965/ipsec-split-dns-new
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm using the site-to-site tunnel, does this stuff work too?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Oh! In that case I think you should configure your local DNS server to forward the related queries to the remote DNS server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Marcos_FDS1012,
In case FortiGate on this side is doing DHCP, you can specify DNS server as remote side so you do not need to manually specify DNS.
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need to enable split DNS, available only for IKEv2 on the later FOS versions.
https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/836965/ipsec-split-dns-new
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm using the site-to-site tunnel, does this stuff work too?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Oh! In that case I think you should configure your local DNS server to forward the related queries to the remote DNS server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Marcos_FDS1012,
In case FortiGate on this side is doing DHCP, you can specify DNS server as remote side so you do not need to manually specify DNS.
Regards,
