Technical Tip: Long Initial Page Load Times Caused by Apple Private Relay and Incomplete DNS Filtering
Description | This article describes how to fix long initial page‑load delay or DNS probe failures on guest Wi‑Fi caused by Apple Private Relay. This behaviour is observed when DNS filter entries for Private Relay mask domains lack explicit block actions. |
Scope | FortiGate-Azure, FortiGate-VM. |
Solution | DNS domain‑filter entries matching mask.icloud.com have no action set, so the DNS queries are resolved normally. Apple Private Relay expects an NXDOMAIN response to immediately disable the feature; In the absence of NXDOMAIN, the client retries TCP/QUIC for ~60–120 seconds before timing out. This is causing the observed delay or DNS probe errors. Disabling QUIC or UTM alone does not force Private Relay off if DNS returns valid addresses; DNS behavior is the decisive signal. Immediate fix: Check each DNS domain‑filter entry for Private Relay explicitly blocks the domain so the client receives a blocking response: Alternative mitigations.
|
