Troubleshooting Tip: DNS Filter profile: Redirect to Fortinet Secure DNS service portal shows error while 'Web Page Blocked!' page is displayed
Description | This article describes why the browser shows the error ‘Not secure’ or ‘Warning’ when the DNS Filter profile redirects to the ‘Fortinet Secure DNS service Portal’.  ![]() |
Scope | FortiGate. |
Solution | Sometimes, when users try to access a website, the following error may be seen: Â If the browser tab has the label 'Fortinet Secure DNS Service Portal', one possible reason behind this is the FortiGate DNS filter. ![]() Â To verify if it is blocked by the DNS filter, follow the steps below:
 ![]()  The default behavior of the DNS filter profile for block action is redirect. It redirects the browser to the Fortinet Secure DNS service portal IP 208.91.112.55:   When FortiGuard Category-Based Filter categories are set to Redirect to Block Portal, the DNS response will use this IP address in its response to the client. If the client is accessing the domain on a web browser, it will be redirected to the block portal page on this address.  It is expected behavior that the browser cannot match the Common Name (CN) FortiGuard SDNS Blocked Page presented by the SDNS portal in the certificate against the blocked domain accessed by the user.  For example, when the user tries to access Python, which belongs to the FortiGuard-based category ‘Information Technology’, and it is blocked by the DNS filter profile, the browser will connect to 208.91.112.55 and receive a certificate with a CN that does not match the request it made.  ![]() ![]()  If the domain is not expected to be blocked, consider checking the expected action based on the DNS filter profile for the domain, or check the FortiGuard server connectivity by using the command diagnose debug rating.  More information on how to create static DNS filters to allow the traffic can be seen in Technical Tip: Static DNS filter to allow/block DNS queries.  More information on FortiGuard server connectivity can be found in Troubleshooting Tip: Resolving FDS Communication Issues (FortiGuard Distribution Servers).  Set the block-action to Redirect.  ![]()
 ![]() Â
 ![]() Â
 The 'Fortinet Secure DNS service Portal' will not block the web page.
 ![]()  For any specific website being blocked where the SDNS page is presented, verify the hostname cache with the following command on FortiGate. In the example below, the aajtak website has a DNS cache with an SDNS block page IP:  For more DNS filter troubleshooting assistance, see Troubleshooting for DNS filter.  Related document: |









