Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
olivierp
New Contributor

Enabling local DNS through VDOMs

Hello,

 

I am working on a Fortigate 600D v5.2.3, build 4944 . I cannot get the local DNS I configured on the unit to work through a transparent vdom, even though it works fine when I plug my computer on an interface in the NAT vdom.

 

On my configuration, the traffic both in and out goes through the transparent vdom, but I use the F600D as a DHCP server and, hopefully, a DNS. For both these options, it seems that I have to configure them in the NAT vdom, and communicate with them using vdom-links.

 

I got the DHCP server to work by:

- giving specific IPs to the virtual interfaces on the vdom-link on the NAT side, and (unrelated) configuring them as ip helper-addresses on the router that connects to the F600D

- creating policies to allow DHCP requests between the virtual interfaces on the vdom-link on the transparent side and the physical interface configured on the transparent vdom

 

I did the same for the DNS, but the DNS never replies when I talk with him through the transparent vdom, for example when I ping a random URL. A packet capture on the NAT interface of the vdom-link shows that the DNS request does arrive there, but no responses are ever sent. When I plug my computer on a physical interface in the NAT vdom and I ping a URL, the DNS will translate the URL as an IP address if it knows it.

 

I tried to show these two scenarios on the small diagram attached to this post. I can copy-paste my CLI configuration for the DHCP server and the DNS-server/database if you wish.

 

Thanks for your help!

0 REPLIES 0
Labels
Top Kudoed Authors