Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mcdaniels
New Contributor

FortiAP: Manipulate DNS to resolv to internal IP

Hi,

is there a possibility to manipulate the DNS lookup for one FQDN  (for specific SSIDs) to resolv to an internal address (LAN-Port)? All other adresses should resolve via public DNS.

 

The policy works, but I have to manipulate the DNS-lookups.

 

I think I will have to activate the fortigate DNS-Server?

 

I don't want to use the hosts file on the clientside.

 

4 REPLIES 4
ede_pfau
Esteemed Contributor III

hi,

 

if the WiFi clients use the FGT as DNS, there is a "DNS translation" feature for this. Basically, the FGT sniffs for DNS requests to this FQDN and exchanges the resolved address. You'll find it in the CLI reference.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
mcdaniels

Hi,

thanks for your reply.

I solved it that way:

-Activated Fortigate DNS Database

-Set up DNS zone / Primary / Slave / recursive

-Set up Host A Entry for internal DNS lookup

-Applied the settings to the SSID in DNS-Database Settings (DNS Server on Interface -> SSID Name)

-Set DNS-Server-IP for the SSID to use same IP as interface IP.

-Set up a Policy from WLAN-SSID to LAN (IP of device I would like to reach via the DNS).

 

Works!

ede_pfau
Esteemed Contributor III

Well done. Quite straightforward once it's done, right?


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
mcdaniels

Hi,

sorry for the delayed respond. Yes, it is pretty straightforward. ;)

Thank you!

Labels
Top Kudoed Authors