Problem Description
We are experiencing a DNS resolution issue in our Dubai office, which has a FortiGate with two ISP links: Etisalat and DU.
Our internal clients are configured to use our internal DNS servers hosted in our AWS backbone network as the primary DNS servers. Public DNS servers such as 8.8.8.8, 8.8.4.4, and 1.1.1.1 are also configured as alternative/fallback resolvers.
When traffic goes through Etisalat, we observe the following:
ping8.8.8.8works successfully, so basic Internet/IP connectivity is available.- Internal domains can be resolved normally through our internal DNS servers.
- Public domains such as
google.comcannot be resolved. - Public DNS resolution does not work as expected.
However, when we switch the ISP link from Etisalat to DU, public DNS resolution starts working immediately without making any changes to the client, DNS, or FortiGate configuration.
In short:
Etisalat: Internet IP connectivity works + internal DNS works + public DNS resolution fails.
DU: Internet IP connectivity works + internal DNS works + public DNS resolution works.
We are trying to understand why public DNS resolution fails only when using the Etisalat link, even though basic Internet connectivity and access to our internal DNS infrastructure are working normally.
Anyone can help us target the scope of the issue?
Source: r/networking · by /u/Zestyclose-Law-6786