When connecting to the FortiSASE service, I seem to be getting directed to a datacenter which isn't the closest one provisioned to my geographic location. What would cause this behavior?
FortiSASE utilizes Anycast GeoDNS hostnames, which are provisioned on a per-customer basis, to direct users to the closest available datacenter(s) provisioned in their instance. These are referred to within the FortiSASE GUI as a “Turbo Hostname”.
As of the time of this writing, you can find the instance Turbo Hostname referenced in multiple sections of the FortiSASE GUI including under the following sections:
The Turbo Hostname will attempt to direct you to the “closest” datacenter based on the specific City, State, or Country you’re located in.
To ensure the most precise direction of traffic, we recommend utilizing a Resolving Name Server which implements the EDNS Client Subnet (ECS) extension. This extension will attempt to forward the specific Source IP or /24 Subnet originating the DNS lookup back to the Authoritative DNS server for a “more specific” answer, rather than using the default answer in cache.
Most traffic direction issues we observe are the result of using a DNS server which does not support this extension, and users being directed to Resolving Name Servers which aren’t physically near their users. This results in poor performance, even outside of the FortiSASE use case (CDNs), as traffic would be directed to servers which aren’t geographically near the user.
If you are sporadically ending up in different datacenters from the same physical location, it’s also possible that your system’s defined Resolving Name Servers are geolocating to different locations.
If you are using a DNS provider which supports the EDNS Client Subnet extension, and require a State or Country-level override, please open a ticket with FortiCare including the troubleshooting steps below. The FortiSASE Ops team can override these values on a per-customer basis as needed on occasion.
Troubleshooting DNS Lookups
For all steps below, you first need to be disconnected from FortiSASE VPN.
FortiAnswers is the space dedicated to FortiSASE and FortiOS questions and suggestions.
3 People are following this question.