Skip to main content
TecnetRuss
Visitor III
June 4, 2020
Question

FortiGuard DNS problems: "no available Fortiguard SDNS servers" & "A rating error occurs"

  • June 4, 2020
  • 2 replies
  • 33784 views

We're noticing this problem across multiple clients this morning.  Any users using Internet access policies with a DNS Filter profile enabled are blocked from accessing the Internet.  The DNS Query logs show constant failures with:

[ul]
  • Error: no available Fortiguard SDNS servers
  • Message: A rating error occurs[/ul]

    The FortiGuard page shows two green "check" status indicators and "diag debug rating" doesn't show any obvious errors.

     

    This is not a config problem.  This has happened simultaneously across multiple FortiGates with known good working configs and no recent config changes.  Changing the FortiGuard protocol and port between UDP and HTTPS, 53, 443 and 8888 doesn't seem to make a difference.  The only solution is to either remove the DNS Filter profile from the policies or set "Allow DNS requests when a rating error occurs" to enabled in the DNS Filter profiles - then traffic starts flowing again.

     

    This seems pretty clearly to be a back-end FortiGuard DNS problem.  Anyone else seeing this?  Any official acknowledgement of any FortiGuard DNS problems?

     

    Russ

    NSE7

    • 2 replies

      dpreston
      New Member
      June 4, 2020

      We have, same description.

      Temp fix for us was to disengage DNS filter component on the IPv4 policy referenced in the log entry.

       

       

      TecnetRuss
      Visitor III
      June 4, 2020

      The problem resolved itself for us at around 12:41 PM Pacific according to my DNS Query logs:

       

      12:41:15 - ERROR- "Message: A rating error occurs" (last error)

      12:41:25 - OK - "Message: Domain belongs to a denied category in policy" (no errors from this point forward)

       

      Russ

      NSE7

      RB4523
      New Member
      June 14, 2020

      We had the same issue the last few days, the following finally got DNS Filtering working again.

       

      config system fortiguard set fortiguard-anycast disable set protocol udp set port 8888 set sdns-server-ip 208.91.112.220 end

       

      Fortigate 6.4.1 

      Ashishdeep
      Staff
      Staff
      October 14, 2024