Fortinet white logo
Fortinet white logo
8.0.3

DNS Services and Security

DNS Services and Security

FortiADC includes a built-in DNS service that allows it to act as an authoritative DNS server for your domains. This DNS capability is tightly integrated with its load balancing features, especially Global Server Load Balancing (GSLB).

Instead of just resolving domain names to IP addresses, FortiADC’s DNS service:

  • Answers DNS queries for your application domains (e.g., www.example.com)

  • Returns intelligent, ordered IP addresses (VIPs)

  • Directs users to the best available application endpoint

Key capabilities
  • Authoritative DNS server

    • Hosts DNS zones for your domain

    • Responds directly to client DNS queries

  • GSLB integration (core value)

    Dynamically generates DNS responses based on:

    • Server health

    • Geographic proximity

    • Performance metrics

  • Health-aware responses

    • Continuously checks backend server availability

    • Excludes failed or unhealthy servers from DNS answers

  • Traffic steering via DNS

    Directs users to:

    • Nearest data center

    • Best-performing server

    • Available failover site

  • DNS security features

    • DNSSEC – ensures DNS response authenticity

    • Response rate limiting – mitigates DNS DDoS attacks

    • DNS forwarding – forwards unresolved queries and caches results

For more information, see Zone and DNS Security and Global DNS Setting in FortiADC Administration Guide.

DNS Services and Security

DNS Services and Security

FortiADC includes a built-in DNS service that allows it to act as an authoritative DNS server for your domains. This DNS capability is tightly integrated with its load balancing features, especially Global Server Load Balancing (GSLB).

Instead of just resolving domain names to IP addresses, FortiADC’s DNS service:

  • Answers DNS queries for your application domains (e.g., www.example.com)

  • Returns intelligent, ordered IP addresses (VIPs)

  • Directs users to the best available application endpoint

Key capabilities
  • Authoritative DNS server

    • Hosts DNS zones for your domain

    • Responds directly to client DNS queries

  • GSLB integration (core value)

    Dynamically generates DNS responses based on:

    • Server health

    • Geographic proximity

    • Performance metrics

  • Health-aware responses

    • Continuously checks backend server availability

    • Excludes failed or unhealthy servers from DNS answers

  • Traffic steering via DNS

    Directs users to:

    • Nearest data center

    • Best-performing server

    • Available failover site

  • DNS security features

    • DNSSEC – ensures DNS response authenticity

    • Response rate limiting – mitigates DNS DDoS attacks

    • DNS forwarding – forwards unresolved queries and caches results

For more information, see Zone and DNS Security and Global DNS Setting in FortiADC Administration Guide.