Hot!Split DNS

Author
nbctcp
Silver Member
  • Total Posts : 89
  • Scores: 4
  • Reward points: 0
  • Joined: 2015/03/05 04:48:26
  • Location: Indonesia
  • Status: offline
2020/01/24 23:43:21 (permalink) 6.2
0

Split DNS

I read somewhere in order to use Web Filter, I need to use FortiGuard DNS
Let say I have internal dns which host all internal server hostname
I want Fortigate which use default fortiguard dns able to solve internal server name
I came with idea to do split dns
OPTION1
-set Fortigate DNS to Internal DNS
set Internal DNS forwarder to FortiGuard DNS
 
OPTION2
-set Fortigate DNS to default FortiGuard DNS
then set

config system dns-database
edit "company1.com"
set domain "company1.com"
set authoritative disable
set forwarder "10.243.13.1"
next
end
 
QUESTIONS
1. Can I do OPTION2 and achieve same result as OPTION1
 
tq
#1

2 Replies Related Threads

    Yurisk
    Bronze Member
    • Total Posts : 22
    • Scores: 2
    • Reward points: 0
    • Joined: 2011/12/04 03:30:01
    • Status: offline
    Re: Split DNS 2020/01/25 01:41:10 (permalink)
    0
    To use Webfilter you don't need to use Fortinet DNSes. To use DNS Filter you do need to use their DNS servers.
    #2
    nbctcp
    Silver Member
    • Total Posts : 89
    • Scores: 4
    • Reward points: 0
    • Joined: 2015/03/05 04:48:26
    • Location: Indonesia
    • Status: offline
    Re: Split DNS 2020/01/25 03:04:52 (permalink)
    0
    https://ibb.co/yNFfcQ8
     
    After seeing Network/DNS/DNS Filter Servers=208.91.112.220
    or
    # sh full-configuration | grep -f sdns-server-ip
    I can see that DNS Filter using FortiGuard
    So OPTION1 should be
    Network/DNS=INTERNAL AD DNS IP
    INTERNAL AD DNS Forwarder=ISP DNS
     
    but question remain, whether can I use OPTION2 and get same result as OPTION1
     
    UPDATE1:
    1. I think this is the answer
    https://www.youtube.com/watch?v=3Ze3jMAdRTo&feature=emb_logo
    I need to setup dns server in Fortigate interface facing LAN/DMZ
     
    Yurisk
    To use Webfilter you don't need to use Fortinet DNSes. To use DNS Filter you do need to use their DNS servers.




    post edited by nbctcp - 2020/01/25 11:37:20
    #3
    Jump to:
    © 2020 APG vNext Commercial Version 5.5