Troubleshooting Tip: Monitoring local out DNS traffic statistics
| Description | This article describes how to monitor local out DNS traffic generated by FortiGate. FortiGate generates DNS queries as local out traffic to resolve domain names required for FortiGate features and services, such as FortiGuard connection, system update, FQDN resolve, certificate verification, and so on. |
| Scope | FortiGate. |
| Solution |
DNS UDP: req=996 res=272 fwd=241 cmp=591 retrans=38 to=17 <----- Req, res fields indicating the number of DNS requests sent by the FortiGate and DNS response received.
Starting from FortiOS v7.6, DNSProxy shows a fail rate as below:
DNS UDP: req=3983 res=3914 fwd=4007 retrans=150 to=58 fail_rate=1.456 <-----
Example output:
diagnose test application dnsproxy 2
DNS TCP connections:
DNS UNIX streams: cfd=35 cfd=36 cfd=37 cfd=38
Related article: Technical Tip: How to enable and view logs for local-out DNS traffic |


