FortiClient writes /etc/resolv.conf itself on connect and never tells resolved a link's DNS. The module now requires split-dns and runs an adapter as root that reads the client's servers and domains from its write, routes them over the client's tunnel through the resolver's socket on the machine, takes the write so the resolver's file is back at once, and takes the route away when the tunnel goes. Nothing of it crosses the bus.