Skip to main content
AKrause
New Member
September 13, 2018
Question

DNS Filter

  • September 13, 2018
  • 4 replies
  • 8270 views

We have recently upgraded to FortiOS 5.4.8 and want to use the DNS-Filter. I have configured a DNS-Filter and applied it to the corresponding firewall policy. Beside some Monitor or Block settings for some categories the DNS-Filter is configured to log all Domains. Where can I see the logs of the DNS-Filter? There is no DNS-Filter category on the Log & Report Section on the local FGT-1500D - nor can I find any logs on the connected FortiAnalyzer.

 

 

    4 replies

    SecurityPlus
    Explorer III
    September 14, 2018
    Under policy Optionshave you tried turning on Log: All Sessions? [link]https://m.youtube.com/watch?v=fY4X4zRilyY[/link]
    Prab
    New Member
    September 17, 2018

    AKrause wrote:

    We have recently upgraded to FortiOS 5.4.8 and want to use the DNS-Filter. I have configured a DNS-Filter and applied it to the corresponding firewall policy. Beside some Monitor or Block settings for some categories the DNS-Filter is configured to log all Domains. Where can I see the logs of the DNS-Filter? There is no DNS-Filter category on the Log & Report Section on the local FGT-1500D - nor can I find any logs on the connected FortiAnalyzer.

     

     

    FortiOS 5.6

    In FortiManager you can view the domains under the Log View -> DNS section:

     

    And on the FGT's GUI under Log & Report -> DNS query

     

    sidenote: In this case the IPv4 policy to which DNS filter was assigned was configured to log the UTM (security events) logs only.

     

    Hope it helps!

    Thanks & regards,

    Prab

     

    AKrause
    AKrauseAuthor
    New Member
    September 18, 2018

    Thanks for your replies. However we are running FOS 5.4

    I raised a ticket at fortinet support. After a lot of ticket pingpong (show screenshots etc..) they finally got the solution: There is no DNS-Filter log in FortiOS 5.4 at all.

    Update to FortiOS 5.6 

     

     

     

    Prab
    New Member
    September 18, 2018

    AKrause wrote:

    Thanks for your replies. However we are running FOS 5.4

    I raised a ticket at fortinet support. After a lot of ticket pingpong (show screenshots etc..) they finally got the solution: There is no DNS-Filter log in FortiOS 5.4 at all.

    Update to FortiOS 5.6 

     

     

     

    Glad that the Support figured it out.

    There is something you could try, I am not sure if it will help:

    Are the clients using the FGT as a DNS? If yes, then you could try creating a normal IPv4 policy for it and log the traffic for this policy. I think in that case you shall see some logs for the DNS request/replies etc.

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!