Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tauriq
New Contributor

VPN Issue on FortiAP 431G version 7.2.2 Build 5072

Good day,

 

We are currently experiencing VPN issues in our Office. We are using Perimeter81, OpenVPN and Global Protect in our office set to Split tunneling. We can connect to the VPN's successfully but are unable to access anything when connected. Please note that this only happens on certain access points. We have 12 x FortiAP 431G Version 7.2.2 Build 5072. After rebooting the access points then it works for a while maybe 3 hours then it does that again.

 

This is the error message that we are getting on the Guest WiFi with DNS set to 1.1.1.1 and 8.8.8.8:

Log Description: "Wireless station DNS process failed with no server response".

Action: DNS-no-resp

Event Message: "DNS server not responding for client".

 

Users connected to the Company Network (Locally Hosted Windows DNS Server) is getting the following:

Log Description: Wireless station DNS process failed due to non-existing domain

Action: DNS-no-domain

Event Message: DNS lookup of wpad.tscpt.local from client b4:6d:83:76:f8:72 failed with "non-existing domain"

 

This only happens when users are connected to WiFi (Company or Guest WiFi). Its working perfectly when the users are connected to LAN.

 

Our environment consists of the following equipment:

2 x Fortigate 200F High Availability (7.2.7 Build 1577)

2 x Fortiswitch 1024E (7.4.1 Build 787)

6 x Fortiswitch 448E-FPOE (7.4.2 Build 801)

12 x FortiAP 431G (7.2.2 Build 5072)

 

Please note I'm new to Fortigate.

 

Thanks

2 REPLIES 2
amrit
Staff
Staff

please check this forum it describes possible reasons of this error https://community.fortinet.com/t5/Support-Forum/Many-quot-DNS-no-domain-quot-errors/m-p/48347?m=1748...

Amritpal Singh
Smith1
New Contributor

Hello, We have the same problem but with FAP 231F and Cisco AnyConnect. The client connects well, an IP address is obtained, but no DNS traffic goes into the tunnel. (ping on the IP OK). This happens for an unknown reason. Other SSIDs on the same FAP 231F continue to work well but no more VPN traffic possible. This happens on some APs and not on others, it is not a configuration problem on the Fortigate. The setup: FAP 231F --> FS 108F-FPOE --> FS 424E --> FG100F Other users have the same problem (reddit): https://www.reddit.com/r/fortinet/comments/16slknr/client_vpn_not_working_while_connected_on_wifi/

Note that this issue was not present with ou previous FG 100E (same FS switch setup and AP)

Thanks

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors