Created on
07-04-2024
03:22 AM
Edited on
09-16-2024
03:00 AM
By
Anthony_E
Description |
This article explains a special case where FortiGate is blocking itself from reaching FortiGuard servers due to a DNS filter. |
Scope |
FortiGate is configured with a DNS filter and an internal DNS server. |
Solution |
In some cases, when the FortiGate loses internet access due to a reboot, power failure, or ISP issue, it may lose connectivity to FortiGuard, causing the web/DNS filters to stop working. For the FortiGate to reconnect to FortiGuard, it will send a DNS query to the configured DNS server to resolve the IP addresses of FortiGuard servers.
Steps:
Debugs when blocked by the DNS filter as below :
[707] __ssl_info_callback: SSLv3/TLS write client hello |