Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Satory
New Contributor III

ZTNA and AD operations

Hi all,

 

I am trying to establish a ZTNA replacement of our VPN for all AD-joined devices.

The first problem I have encountered is that workstations cannot resolve the domain controllers - our internal DNS server is accessible on TCP 53, but it tries UDP 53 to the DHCP provided DNS server of my remote users.

 

So my users are unable to change their passwords, force local password changes and etc.

 

Does anyone succeeded in establishing ZTNA for AD environment?

2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Satory

As per my knowledge regular clients use UDP 53 for DNS, not TCP 53 (please double check).

TCP 53 is used in few specific cases, like zone transfer between DNS servers.

AEK
AEK
Satory
New Contributor III

You are not correct - you may fallback and use tcp 53, the problem is that windows uses udp by default.

Still I can't believe no one uses ZTNA for AD access...

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors