Troubleshooting Tip: DNS filter is giving rating errors, even though there is connectivity to the SDNS servers
| Description | This article describes a scenario where the SDNS servers are replying to the FortiGate for DNS ratings, yet the DNS filter is still reporting rating errors |
| Scope | FortiOS, DNS filter |
| Solution | When looking at the logs for the DNS filter, and queries are getting blocked due to rating errors, this is usually a network related issue. If it is possible to see the SDNS server reply in a PCAP/sniffer and this error is still seen, the FortiGate may be hitting a unique scenario. The following screenshot is an example of this response, with the TXT record included:
It is possible to see that the TXT record is missing. This can be caused if the ISP or a device in between the FortiGate and the internet are doing some sort of DNS inspection, and are stripping this record off the response. |

