Fortinet black logo

Version:


Table of Contents

FortiGate NGFW to FortiSASE SPA Hub Conversion Deployment Guide

Download PDF
Copy Doc ID 66d7cd51-4d9c-11ee-8e6d-fa163e15d75b:264801
Copy Link

Configuring DNS Settings

The Default DNS Server setting in FortiSASE is used by agent-based remote users to resolve hostnames for both internal and external domains.

By default, FortiSASE deployments use FortiGuard DNS as the default DNS server.

You can configure the Default DNS Server with one of the following options and then click OK to save the change:

DNS Server

 

Description

Primary and Secondary DNS Server IP Address

FortiGuard DNS

 

Use FortiGuard DNS

208.91.112.53

208.91.112.52

Use endpoints' system DNS

 

Use the system DNS setting already configured on the agent-based endpoints IP addresses specific to endpoints
Other DNS

 

Use a public DNS server other than FortiGuard DNS IP addresses specific to public DNS server
 

CloudFlare

Use the CloudFlare public DNS server

1.1.1.1

1.0.0.1

 

Google

Use the Google public DNS server

8.8.8.8

8.8.4.4

 

Quad 9

Use the Quad 9 public DNS server

9.9.9.9

149.112.112.112

Using FortiGuard DNS or another public DNS service is sufficient for most agent-based Secure Internet Access (SIA) use cases that simply require agent-based remote users to resolve hostnames for external domains.

Configuring DNS Settings

The Default DNS Server setting in FortiSASE is used by agent-based remote users to resolve hostnames for both internal and external domains.

By default, FortiSASE deployments use FortiGuard DNS as the default DNS server.

You can configure the Default DNS Server with one of the following options and then click OK to save the change:

DNS Server

 

Description

Primary and Secondary DNS Server IP Address

FortiGuard DNS

 

Use FortiGuard DNS

208.91.112.53

208.91.112.52

Use endpoints' system DNS

 

Use the system DNS setting already configured on the agent-based endpoints IP addresses specific to endpoints
Other DNS

 

Use a public DNS server other than FortiGuard DNS IP addresses specific to public DNS server
 

CloudFlare

Use the CloudFlare public DNS server

1.1.1.1

1.0.0.1

 

Google

Use the Google public DNS server

8.8.8.8

8.8.4.4

 

Quad 9

Use the Quad 9 public DNS server

9.9.9.9

149.112.112.112

Using FortiGuard DNS or another public DNS service is sufficient for most agent-based Secure Internet Access (SIA) use cases that simply require agent-based remote users to resolve hostnames for external domains.