Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Yogev
New Contributor

fortigate - forward all network traffic through specific dns server

Hello,

I will like to forward all DNS queries at my network to go through a safer DNS server like 9.9.9.9. This is the current configuration - My DHCP server is the FortiGate and it is directed to a DNS server at my network. I will like to keep the DNS server as it is but instead of sending the queries to my ISP DNS server I want it to run through the quad9 DNS server. Any ideas?
1 REPLY 1
ede_pfau
SuperUser
SuperUser

Create a VIP which redirects (destination NAT) your ISP's DNS address to quad9.

external address: 1.2.3.4 (your ISP's DNS)

mapped-to: 9.9.9.9

 

no port forwarding.

 

Then, create a policy

from LAN

to WAN

src addr LAN/24

dest addr: this_VIP

service: DNS

 

and query with "nslookup" from a host.

I use this to reduce NTP queries by redirecting them to the FGT LAN interface, and using the FGT as NTP server. Sometimes this is easier than walk around and change so many devices...


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors