AnsweredHot!Strange DNS Issue some site not accessable

Author
Akbar ali
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/10/24 00:44:02
  • Status: offline
2017/10/24 00:52:52 (permalink)
0

Strange DNS Issue some site not accessable

we have an issue in our DNS could be from fortigate, could be the traffic route not define correctly. The Scenario is
we have 2 ISP connections both are directly connected to Fortigate 100D version 5.4.5.1138. server subnet going to DIA link and PC subnet going to DSL link. but pcs are getting DNS from AD server. now the problem is i cannot access MSN, DHL and Turkishairline sites unless i use 8.8.8.8 or DSL gateway IP.
#1
rwpatterson
Expert Member
  • Total Posts : 8040
  • Scores: 157
  • Reward points: 0
  • Joined: 2006/08/08 10:08:18
  • Location: Long Island, New York, USA
  • Status: online
Re: Strange DNS Issue some site not accessable 2017/10/24 12:54:30 (permalink) ☼ Best Answerby Akbar ali 2017/10/26 02:06:02
5 (1)
Most carriers will only answer requests for their subnets. 8.8.8.8 (Google DNS) will answer queries from anywhere. That is what is know as an open DNS server. If your AD DNS server was configured correctly, then all agents using it should be able to get DNS queries from anywhere. I would look closer into that box to see if maybe it is passing queries through instead of interpreting (recursing) those queries. Also if you DIA link is reaching the primary link DNS server, this could prevent queries from completing for the above reason. Since the query is coming from an IP address on the DIA side, the primary will just drop it. Either choose a neutral server, or make sure that all DNS queries exit from the path you need them to.
 
Hope that wasn't too long winded.

-Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

-4.3.18-b0689
FGT60B
FWF60B
FWF80CM (2)
FWF81CM
 
#2
Akbar ali
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/10/24 00:44:02
  • Status: offline
Re: Strange DNS Issue some site not accessable 2017/10/26 02:06:53 (permalink)
0
The problem solved. as i explained i have 2 ISP so the pc traffic going through DSL and server traffic to DIA and in domain controller Forwarder configure for DIA DNS. which may be conflict. what i did i add DSL gateway as a Forwarder and create policy in fortinet under DSL interface so domain controller traffic can go through the same link where i need traffic.
#3
Jump to:
© 2017 APG vNext Commercial Version 5.5