I am setting up an iOS IPSec VPN and followed everything in this guide
https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/311726/ios-device-as-dialup-...
So far I can access the local network but only via IPs. Hostnames does not work. Clients can ping the dns server but the client can't seem to get any resolution.
Is there a problem in this guide or lacking any steps? I tried to search other KB but seem to not work either.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Check if the port 53 (DNS) traffic is allowed . Also, take a packet capture on the incoming and outgoing interfaces of the firewall. You can run the following debugs
di de flow filter addr <src machine ip>
di de flow filter port 53
di de flow show function-name en
di de flow trace start 100
di de en
On a separate CLI run the following
di sniffer packer any 'host <dns ip> and port 53' 4 0 l
Initiate the DNS request and provide the output from the above debugs
To disable debugs
di de dis
Hello @maplesyrup
Can you please check this document: make sure dns suffix is set on the ipsec phase1 configuration
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1545 | |
1030 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.