Skip to main content
jmlux
New Member
November 4, 2015
Question

strange DNS traffic

  • November 4, 2015
  • 1 reply
  • 18061 views

Hello all,

 

We have noticed non-DNS traffic on port 53 from the Fortigate to the Internet (because we have another firewall between the Fortigate and the Internet ;) )

 

1.2.3.4 1798 208.91.112.196 53 udp flow from InternetTransit:1.2.3.4/1798 to Internet:208.91.112.196/53 terminated by inspection engine, reason - inspector disconnected, dropped packet.

 

Wireshark shows this:

 

What is that??

    1 reply

    Sylvia
    Explorer
    November 4, 2015

    Most probably this is the Fortiguard Communication for Webfilter and Antispam to the Fortiguard Server.

    Check in the WebUI: System > Fortiguard, go to the bottom and open "Webfilter and Antispam".

    Here you can configure if the Fortigate should use port 53 or port 8888 for the communication.

     

    Regards,

    Sylvia

    jmlux
    jmluxAuthor
    New Member
    November 5, 2015

    Sylvia wrote:

    Most probably this is the Fortiguard Communication for Webfilter and Antispam to the Fortiguard Server.

    Check in the WebUI: System > Fortiguard, go to the bottom and open "Webfilter and Antispam".

    Here you can configure if the Fortigate should use port 53 or port 8888 for the communication.

    But we have that disabled anyway.

    Ian_Harrison
    New Member
    November 6, 2015

    Hi

     

    Looks like you have disabled the push updates from Fortiguard to your device, however scheduled update requests from your device to Fortiguard are still enabled on port 53.  As mentioned you can change this to port 8888. 

     

    Also the IP address 208.91.112.196 is in the range owned by Fortinet so probably one of their Fortiguard servers.  

     

    Hope that helps

     

    Ian