Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kiandra
New Contributor

SSL VPN IP pools

Currently the FortiGates only support one DNS server that gets assigned to all VPN pools. Setting up the DNS to client or specify applies to all VPN users.

Will it be possible to add a feature where you can assign specific DNS server for every pool or user?

Eg. UserA pool 10.1.1.1-10.1.1.10 DNS 1.1.1.1

      UserB pool 10.2.2.2-10.2.2.10 DNS 2.2.2.2

Centralising every VPN user to a specific DNS may expose some information leakage risks. If the DNS configured is an internal one (which in most case will be the case to reach the internal servers by FQDN), and you configure a separate VPN pool of users with limited access, these can still query the DNS servers and map out the internal server/client names.

 

4 REPLIES 4
ede_pfau
SuperUser
SuperUser

So your SSLVPN users are not trustworthy? Might be the real problem behind this scenario.

 

I guess you could configure a static DNS in the FC config (via XML exported config & editing). Another approach might be to specify only one central DNS without any zones which then forwards requests according to source address of the request.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Kiandra

Hi, 

 

the idea would have half trusted and half not trusted. The trusted ones can use the internal DNS while the non a different one. I thought of creating a DNS server with ACLs on the zones, but it does create more complexity. 

 

It would've been easier just to add a DNS server for every pool. There are other firewalls which can do this, reason of requesting it as a feature...

rdumitrescu
New Contributor III

Hi,

you can set different DNS server for different IP Pool if you create one portal for any IP Pool

 

The portal settings have priority on the global settings

Kiandra

You are right. Support told me that it could't be done, including other higher level engineers, and portal is only for IP pools but not DNS. The GUI doesn't have anything about DNS. I went digging in the CLI through the portals and found the DNS.

 

FortiOS still has many things missing in the GUI.

Labels
Top Kudoed Authors