How do you implement split DNS (split-horizon DNS) with FortiGate?

Study for the FCP FortiGate Administrator 7.6 Test. Engage with flashcards and multiple choice questions, each question is supported with hints and explanations to enhance your knowledge. Prepare thoroughly for your exam!

Multiple Choice

How do you implement split DNS (split-horizon DNS) with FortiGate?

Explanation:
Split DNS means giving internal clients different DNS answers than external users, so internal domains resolve to internal hosts while external queries use public resolvers. FortiGate can implement this by directing internal domain lookups to your internal DNS servers and letting external queries go to external resolvers, with policies that enforce who uses which path. In practice, you set up internal DNS resolution for the internal zones using your own DNS servers, and on FortiGate configure rules—such as domain overrides or DNS forwarding policies—to forward those internal-domain queries to the internal servers. For anything outside those internal zones, FortiGate forwards to external DNS resolvers. This approach keeps internal names and addresses private while still allowing external users to resolve public names. Other options don’t fit because using a single DNS resolver eliminates the separation between internal and external views; relying solely on FortiGuard DNS provides only external resolution and doesn’t route internal domains to internal servers; and disabling internal DNS resolution removes the ability for internal hosts to resolve internal names at all.

Split DNS means giving internal clients different DNS answers than external users, so internal domains resolve to internal hosts while external queries use public resolvers. FortiGate can implement this by directing internal domain lookups to your internal DNS servers and letting external queries go to external resolvers, with policies that enforce who uses which path. In practice, you set up internal DNS resolution for the internal zones using your own DNS servers, and on FortiGate configure rules—such as domain overrides or DNS forwarding policies—to forward those internal-domain queries to the internal servers. For anything outside those internal zones, FortiGate forwards to external DNS resolvers. This approach keeps internal names and addresses private while still allowing external users to resolve public names.

Other options don’t fit because using a single DNS resolver eliminates the separation between internal and external views; relying solely on FortiGuard DNS provides only external resolution and doesn’t route internal domains to internal servers; and disabling internal DNS resolution removes the ability for internal hosts to resolve internal names at all.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy