Skip to main content
dan_newcombe
New Member
February 8, 2018
Question

Slow DNS resolution due to DNS Filter

  • February 8, 2018
  • 1 reply
  • 29001 views

I noticed in the last few weeks that Chrome would pause a lot with "Resolving Host...".  Of course, I blamed Chrome, addons, my machine, etc.   

 

But eventually I realized it wasn't me.  Our DNS servers were seeing this slowness.  Occasionally nslookup would timeout with the DNS server not returning a response in time, because it wasn't receiving one in time. What I finally tracked it down to is our Fortigate.  We have DNS filtering turned on for our Internet policy, and are using category filtering.   Once I turned that off, everything returned to normal fast operation, including no slowness with nslookup/dig. Is this normal when this filter is enabled?   Our DNS servers are set to use Google's DNS as their forwarders.  Don't know if it would help to change that to something else making it easier for Fortigate to see the requests faster. Thanks

    1 reply

    ThunderSpartan
    New Member
    February 8, 2018
    We were having this issue as well, and thanks to your post I turned off the “FortiGuard category based filter” on the DNS filter, and our page loading is much better, we would get time-outs at times loading pages and I have been making changes to our DNS to try and resolve. Hopefully one of the gurus on this forum can explain. Thanks
    bbahes
    New Member
    March 15, 2018

    We also had this problem ever since I turned on DNS Filter. I had to change option "Use Fortiguard servers" to Specify and use DNS servers provided by our ISP.

    dan_newcombe
    New Member
    March 15, 2018

    We were already using our own DNS servers.  I mean to come back and followup.  Basically, about a week after my original post everything just starting working fine again.   Ah...Internet....