Configuring DNS Settings
Agent-based remote users use the VPN Implicit DNS Rule setting in FortiSASE under Configuration > DNS to resolve hostnames for internal and external domains.
By default, FortiSASE deployments use FortiGuard DNS as the default DNS server.
You can configure the VPN Implicit DNS Rule with one of the following options and then click OK to save the change:
DNS Server
|
Description |
Primary and Secondary DNS Server IP Address |
|
---|---|---|---|
FortiGuard DNS
|
Use FortiGuard DNS |
208.91.112.53 208.91.112.52 |
|
Use endpoints' system DNS
|
Use the system DNS setting already configured on the agent-based endpoints | IP addresses specific to endpoints | |
Other DNS
|
Use a public DNS server other than FortiGuard DNS | IP addresses specific to public DNS server | |
CloudFlare |
Use the CloudFlare public DNS server |
1.1.1.1 1.0.0.1 |
|
|
Custom | Enable to specify your own custom primary and secondary DNS servers.. | Specify IP address of primary and secondary DNS. |
|
Use the Google public DNS server |
8.8.8.8 8.8.4.4 |
|
Quad 9 |
Use the Quad 9 public DNS server |
9.9.9.9 149.112.112.112 |
For example, you can edit the VPN implicit DNS rule to use a custom DNS server as follows:
To configure a custom DNS server:
- Go to Configuration > DNS, select VPN Implicit DNS Rule, and click Edit.
- In the Edit Implicit DNS Rule page, for Default DNS Server, select Other DNS.
- From the DNS Server dropdown, select Custom.
- In the Primary DNS Server and Secondary DNS Server fields, enter the respective IP addresses for the servers of your choice.
- Click OK.
Using FortiGuard DNS or another public DNS service is sufficient for most agent-based Secure Internet Access (SIA) use cases that simply require agent-based remote users to resolve hostnames for external domains.