Skip to main content
ChrisTan
Staff
Staff
October 13, 2022

Technical Tip: DNS Filter Rating Servers 'Unreachable' when DNS over TLS is configured with third party certificate

  • October 13, 2022
  • 0 replies
  • 9147 views

Description

This article describes that if DNS is enabled over TLS with the default 'Fortinet_Factory', DNS Filter Rating Servers work fine.


But if is selected with any other third-party certificate, DNS Filter Rating Servers would be 'Unreachable'.

Scope

FortiGate.

Solution

Below is the log for DNS rating:

 

2022-09-14 15:05:18 [worker 0] _dns_tcps_conn_rating_write()-477: domain= buf=0x7f05f4f2bc40 sz=112 off=0
2022-09-14 15:05:18 [worker 0] dns_tcps_conn_read()-617: from 0.0.0.0:0 mode=0 vfid=0 status=5
2022-09-14 15:05:18 [worker 0] dns_tcps_conn_read()-625: buf=0x7f05f4fb23c8 off=0 pkt=0x7f05f4fb23c8 pkt_off=0 pkt_sz=0
2022-09-14 15:05:18 [worker 0] dns_tcps_conn_read()-640: remote host closed connection  <-----
2022-09-14 15:05:18 [worker 0] dns_tcps_conn_close()-362: close connection from 0.0.0.0:0 to 173.243.140.53:853 mode=0 vfid=0
2022-09-14 15:05:19 [worker 0] dns_retransmit_func()-1649: jiffies=1064544992 created=1064543844 wait_cat=1 wait_res=0 profile=
last_tx=0 ftg_last_tx=0 domain= (orig id: 0x1203 local id:0x1203 active)


It shows that the FortiGuard DNS server closed the connection for DNS over TLS (DoT) requests on port 853.

 

This is normal behavior as the authentication is against FortiGuard servers and the connection will be refused if a certificate without the SN of the FortiGate is used.

To resolve this, use a default FortiGate certificate.

Screenshot 2025-08-09 104215.png


From the CLI:

config system dns
    set ssl-certificate "Fortinet_Factory"
end


Note: If the issue persists after using the default FortiGate certificate, open a ticket with Fortinet TAC and ask for Support to check the situation.

Refer to: Technical Tip: How to create a ticket for Fortinet TAC.

Related article:

Troubleshooting Tip: DNS unreachable when configured with DNS over TLS on FortiGate after upgarde to v7.4.10

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!