Hot!DNS forwarding to seperate servers

Author
simonorch
Gold Member
  • Total Posts : 315
  • Scores: 12
  • Reward points: 0
  • Joined: 2009/06/05 00:05:08
  • Location: Norway
  • Status: offline
2019/01/18 02:38:40 (permalink) 5.4
0

DNS forwarding to seperate servers

I have a guest network which is routed to the internet via a seperate vlan on the wan side. 
The guest network uses a a captive portal on a different network, in order to implement https for the captive portal i need clients to dns resolve the CP url, this i can do with a dns database on the FG and setting dhcp to use the FG interface for dns.
This works fine except for one thing.
Forwarding uses the DNS servers configured on the FG, the forwarders configured on the dns database only work for that domain, all other dns lookups use the box dns servers. This is a problem that creates a lot of extra configuration work arounds.
 
The Question is. Is it possible to define specific DNS forwarders for a specific vlan/net  and not use the 'default' DNS servers configured on the box which are used for all other non-guest network DNS?
 
what i mean is.
 
let's say the FG is configured with 10.10.10.10 as a dns server
 
vlan 10 dhcp is configured to use the FG interface as DNS so that clients can resolve an internal captive portal. but i want DNS forwarding to use 8.8.8.8 and not 10.10.10.10
 
hope that makes sense
 
Simon

FCNSP V.4, V.5, NSE5
Fortinet platinum partner - Norway
#1

2 Replies Related Threads

    Dave Hall
    Expert Member
    • Total Posts : 1340
    • Scores: 138
    • Reward points: 0
    • Joined: 2012/05/11 07:55:58
    • Location: Canada
    • Status: offline
    Re: DNS forwarding to seperate servers 2019/01/18 07:47:43 (permalink)
    0
    What's preventing you from manual setting the DNS servers on the DHCP server settings for the interface?
     
    Edit:  Set up a recursive DNS server for the guest network and add a record for the captive portal.
     
    post edited by Dave Hall - 2019/01/18 08:59:47

    NSE4/FMG-VM64/FortiAnalyzer-VM/5.2/5.4 (FWF40C/FW92D/FGT200B/FGT200D/FGT101E)/ FAP220B/221C
    #2
    simonorch
    Gold Member
    • Total Posts : 315
    • Scores: 12
    • Reward points: 0
    • Joined: 2009/06/05 00:05:08
    • Location: Norway
    • Status: offline
    Re: DNS forwarding to seperate servers 2019/01/18 09:33:08 (permalink)
    0
    Thanks but already done. The problem is the forwarders. The work around i have at the moment is to configure the guest network public DNS servers as the fortigate DNS servers and all other networks using dhcp to use the company internal dns servers. It works but isn't ideal as this will be pushed out to over 600 boxes and to ensure it can work i need to add a few per location unique source IPs and static routes
     
    Ideally it would be great if you could configure custom dns forwarders on each interface dns service
     
    Simon

    FCNSP V.4, V.5, NSE5
    Fortinet platinum partner - Norway
    #3
    Jump to:
    © 2019 APG vNext Commercial Version 5.5