This article outlines a change in behavior in how FortiGate handles QUIC traffic, starting from v7.4.2 and higher. It describes enhanced QUIC control options and describes how this impacts browser performance and traffic handling in environments with specific DNS or proxy configurations.
FortiGate v7.4.2 and above.
From v7.4.2 and above, FortiGate has three QUIC options within the SSL/SSH inspection profile:
config firewall ssl-ssh-profile
edit <name>
config https
set quic {inspect | bypass | block}
end
config dot
set quic {inspect | bypass | block}
end
next
end
Available options for the QUIC setting:
Observed behavior:
Browsers using experimental QUIC or DNS over QUIC (e.g., Cisco Umbrella Cloud Proxy) may experience:
Cause:
Recommendations:
To properly handle or block QUIC traffic under the new behavior, apply one of the following methods:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.