Fortinet white logo
Fortinet white logo

CLI Reference

config dns

config dns

Description: Configure DNS settings used to resolve domain names to IP addresses.

config dns

set primary {ipv4-address}

set secondary {ipv4-address}

set timeout [1 – 10]

set retry [0 – 5]

set dns-cache-limit [0 – 4294967295]

set dns-cache-ttl [60 – 86400]

set cache-notfound-response [enable | disable]

set source-ip {ipv4-address}

set server-select-method [least-rtt | failover]

unset

show

end

Sample command:

FX201E5919000057 (dns) # show
config system dns
    set primary 208.91.112.53
    set secondary 208.91.112.52
    set timeout 5
    set retry 3
    set dns-cache-limit 5000
    set dns-cache-ttl 1800
    set cache-notfound-responses disable
    set source-ip 0.0.0.0
    set server-select-method least-rtt
end
Parameter Description Type Size Default
primary Primary DNS server IP address. The default is the FortiGuard primary DNS server IP. IPv4 address - 208.91.112.53
secondary Secondary DNS server IP address. The default is the FortiGuard secondary DNS server. IPv4 address - 208.91.112.52
timeout DNS query timeout interval in seconds. integer 1 - 10 5
retry Number of times to retry. integer 0 - 5 3
dns-cache-limit Maximum number of records in DNS cache. integer 0 - 4294967295 5000
dns-cache-ttl Duration in seconds that DNS cache retains information. integer 60 - 86400 1800
cache-notfound-responses Status of response from the DNS server when a record is not in cache. option - disable

Option Description
enable Enable cache-notfound-responses.
disable Disable cache-notfound-responses.

source-ip

IP address used by the DNS server as its source IP.

IPv4 address

-

0.0.0.0

server-select-method The way in which configured servers are prioritized. option - least-rtt

Option Descrption
least-rtt least-rtt as server-select-method.
failover failover as server-select-method.

config dns

config dns

Description: Configure DNS settings used to resolve domain names to IP addresses.

config dns

set primary {ipv4-address}

set secondary {ipv4-address}

set timeout [1 – 10]

set retry [0 – 5]

set dns-cache-limit [0 – 4294967295]

set dns-cache-ttl [60 – 86400]

set cache-notfound-response [enable | disable]

set source-ip {ipv4-address}

set server-select-method [least-rtt | failover]

unset

show

end

Sample command:

FX201E5919000057 (dns) # show
config system dns
    set primary 208.91.112.53
    set secondary 208.91.112.52
    set timeout 5
    set retry 3
    set dns-cache-limit 5000
    set dns-cache-ttl 1800
    set cache-notfound-responses disable
    set source-ip 0.0.0.0
    set server-select-method least-rtt
end
Parameter Description Type Size Default
primary Primary DNS server IP address. The default is the FortiGuard primary DNS server IP. IPv4 address - 208.91.112.53
secondary Secondary DNS server IP address. The default is the FortiGuard secondary DNS server. IPv4 address - 208.91.112.52
timeout DNS query timeout interval in seconds. integer 1 - 10 5
retry Number of times to retry. integer 0 - 5 3
dns-cache-limit Maximum number of records in DNS cache. integer 0 - 4294967295 5000
dns-cache-ttl Duration in seconds that DNS cache retains information. integer 60 - 86400 1800
cache-notfound-responses Status of response from the DNS server when a record is not in cache. option - disable

Option Description
enable Enable cache-notfound-responses.
disable Disable cache-notfound-responses.

source-ip

IP address used by the DNS server as its source IP.

IPv4 address

-

0.0.0.0

server-select-method The way in which configured servers are prioritized. option - least-rtt

Option Descrption
least-rtt least-rtt as server-select-method.
failover failover as server-select-method.