Skip to main content
rtoko
New Member
December 4, 2014
Question

DNS deny

  • December 4, 2014
  • 4 replies
  • 45734 views

Hi, I after upgrade of FGT60D to 5.2.2. policy is behaving very strange, at least one...

For example I have policy ACCEPT from internal (LAN) to WAN for service ALL .. in short to internet. Now after upgrade http/https is not working, but for example Skype is working normally. So I figured it out that there is something wrong with DNS. So I made new policy just for DNS and now http/https is working.

 

So my question is why is this necessary after upgrade!? Is it not enough to use SERVICE "ALL"!?

 

Regards

    4 replies

    ede_pfau
    SuperUser
    SuperUser
    December 4, 2014

    Is that a user authenticated policy? DNS used to be allowed implicitly on IBP but is not in v5.2.

    rtoko
    rtokoAuthor
    New Member
    December 4, 2014

    No it is not user authenticated policy just from one to another interface ... if I use for service "ALL_TCP" and "ALL_UDP" under "GENERAL" everything is working, just not "ALL" ....

    Jeff_FTNT
    Staff
    Staff
    December 4, 2014

    It have a bug.

     

    Please check it with CLI:show  full firewall  service  custom  ALL

    evision_support
    New Member
    December 5, 2014

    I confirm a similar issue with the same build of FortiOS on a FortiWifi 60C.

     

    In our case, on this specific FortiWifi, we also have a policy that allows all outbound traffic from an internal network to the Internet on all ports/protocols (using the ALL service). Until the update to the 5.2 branch, there was no issues with this rule. After the update to the latest release, users began reporting issues with their Internet access. In the logs, we have seen there were many entries about denied DNS requests and labeled with a threat level of "high", which is rather strange.

     

    After 2 hours of trial and error and some "googling", we have added a new policy that explicitly accepts outbound DNS requests. And then the Internet connectivity was back. We have later refined the rule to only add those services really needed.

     

    Cindy B.

     

     

     

     

    houssem_alios
    New Member
    April 7, 2016

    Hi

    i have the same issue with "Deny: DNS error Fortigate" error.

    But even when i added the policy for outbound requests DNS, i have the same error on forward traffic.

    so if there are same news about any solutions on this issue please let me know.

     

    I have : FORTIGATE 60D with 5.4 build

     

    Regards.

     

    hanjan
    New Member
    April 21, 2016

    Hi Houssem.Alios!

    Did you try to enable "Allow and log DNS traffic" under the Application Control Security Profile?

     

    Br,

    Jan-Ivar