Created on 07-04-2024 03:22 AM Edited on 09-16-2024 03:00 AM By Anthony_E
Description |
This article explains a special case where FortiGate is blocking itself from reaching FortiGuard servers due to a DNS filter. |
Scope |
FortiGate is configured with a DNS filter and an internal DNS server. |
Solution |
In some cases, when the FortiGate loses internet access due to a reboot, power failure, or ISP issue, it may lose connectivity to FortiGuard, causing the web/DNS filters to stop working. For the FortiGate to reconnect to FortiGuard, it will send a DNS query to the configured DNS server to resolve the IP addresses of FortiGuard servers.
Steps:
Debugs when blocked by the DNS filter as below :
[707] __ssl_info_callback: SSLv3/TLS write client hello |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.