Fortinet white logo
Fortinet white logo

FortiGate NGFW to FortiSASE SPA Hub Conversion Deployment Guide

Configuring DNS Settings

Configuring DNS Settings

Remote users use VPN Implicit DNS Rule in FortiSASE under Configuration > DNS to resolve hostnames for internal and external domains.

By default, FortiSASE deployments use FortiGuard DNS as the default DNS server.

You can edit VPN Implicit DNS Rule and configure Default DNS Server with one of the following options and then click OK to save the change:

DNS Server

Description

Primary and secondary DNS server IP address

FortiGuard DNS Use FortiGuard DNS

208.91.112.53

208.91.112.52

Use endpoints' system DNS Use the system DNS setting already configured on the agent-based endpoints IP addresses specific to endpoints
Other DNS Use a public DNS server other than FortiGuard DNS IP addresses specific to public DNS server

CloudFlare

Use the CloudFlare public DNS server

1.1.1.1

1.0.0.1

Custom

Enable to specify your own custom primary and secondary DNS servers

Specify IP address of primary and secondary DNS

Google

Use the Google public DNS server

8.8.8.8

8.8.4.4

Quad 9

Use the Quad 9 public DNS server

9.9.9.9

149.112.112.112

For example, you can edit the VPN implicit DNS rule to use a custom DNS server as follows:

To configure a custom DNS server:
  1. Go to Configuration > DNS, select VPN Implicit DNS Rule, and click Edit.
  2. In the Edit Implicit DNS Rule page, for Default DNS Server, select Other DNS.
  3. From the DNS Server dropdown, select Custom.

  4. In the Primary DNS Server and Secondary DNS Server fields, enter the respective IP addresses for the servers of your choice.

  5. Click OK.

Using FortiGuard DNS or another public DNS service is sufficient for most agent-based Secure Internet Access (SIA) use cases that simply require agent-based remote users to resolve hostnames for external domains.

Configuring DNS Settings

Configuring DNS Settings

Remote users use VPN Implicit DNS Rule in FortiSASE under Configuration > DNS to resolve hostnames for internal and external domains.

By default, FortiSASE deployments use FortiGuard DNS as the default DNS server.

You can edit VPN Implicit DNS Rule and configure Default DNS Server with one of the following options and then click OK to save the change:

DNS Server

Description

Primary and secondary DNS server IP address

FortiGuard DNS Use FortiGuard DNS

208.91.112.53

208.91.112.52

Use endpoints' system DNS Use the system DNS setting already configured on the agent-based endpoints IP addresses specific to endpoints
Other DNS Use a public DNS server other than FortiGuard DNS IP addresses specific to public DNS server

CloudFlare

Use the CloudFlare public DNS server

1.1.1.1

1.0.0.1

Custom

Enable to specify your own custom primary and secondary DNS servers

Specify IP address of primary and secondary DNS

Google

Use the Google public DNS server

8.8.8.8

8.8.4.4

Quad 9

Use the Quad 9 public DNS server

9.9.9.9

149.112.112.112

For example, you can edit the VPN implicit DNS rule to use a custom DNS server as follows:

To configure a custom DNS server:
  1. Go to Configuration > DNS, select VPN Implicit DNS Rule, and click Edit.
  2. In the Edit Implicit DNS Rule page, for Default DNS Server, select Other DNS.
  3. From the DNS Server dropdown, select Custom.

  4. In the Primary DNS Server and Secondary DNS Server fields, enter the respective IP addresses for the servers of your choice.

  5. Click OK.

Using FortiGuard DNS or another public DNS service is sufficient for most agent-based Secure Internet Access (SIA) use cases that simply require agent-based remote users to resolve hostnames for external domains.