Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Akbar_ali
New Contributor

Strange DNS Issue some site not accessable

we have an issue in our DNS could be from fortigate, could be the traffic route not define correctly. The Scenario is

we have 2 ISP connections both are directly connected to Fortigate 100D version 5.4.5.1138. server subnet going to DIA link and PC subnet going to DSL link. but pcs are getting DNS from AD server. now the problem is i cannot access MSN, DHL and Turkishairline sites unless i use 8.8.8.8 or DSL gateway IP.

1 Solution
rwpatterson
Valued Contributor III

Most carriers will only answer requests for their subnets. 8.8.8.8 (Google DNS) will answer queries from anywhere. That is what is know as an open DNS server. If your AD DNS server was configured correctly, then all agents using it should be able to get DNS queries from anywhere. I would look closer into that box to see if maybe it is passing queries through instead of interpreting (recursing) those queries. Also if you DIA link is reaching the primary link DNS server, this could prevent queries from completing for the above reason. Since the query is coming from an IP address on the DIA side, the primary will just drop it. Either choose a neutral server, or make sure that all DNS queries exit from the path you need them to.

 

Hope that wasn't too long winded.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

View solution in original post

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
2 REPLIES 2
rwpatterson
Valued Contributor III

Most carriers will only answer requests for their subnets. 8.8.8.8 (Google DNS) will answer queries from anywhere. That is what is know as an open DNS server. If your AD DNS server was configured correctly, then all agents using it should be able to get DNS queries from anywhere. I would look closer into that box to see if maybe it is passing queries through instead of interpreting (recursing) those queries. Also if you DIA link is reaching the primary link DNS server, this could prevent queries from completing for the above reason. Since the query is coming from an IP address on the DIA side, the primary will just drop it. Either choose a neutral server, or make sure that all DNS queries exit from the path you need them to.

 

Hope that wasn't too long winded.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Akbar_ali
New Contributor

The problem solved. as i explained i have 2 ISP so the pc traffic going through DSL and server traffic to DIA and in domain controller Forwarder configure for DIA DNS. which may be conflict. what i did i add DSL gateway as a Forwarder and create policy in fortinet under DSL interface so domain controller traffic can go through the same link where i need traffic.

Labels
Top Kudoed Authors