This article outlines the change in behavior related to how FortiGate handles QUIC traffic, starting from v7.4.5 and continuing later. It introduces enhanced QUIC control options and describes how this impacts browser performance and traffic handling in environments with specific DNS or proxy configurations.
FortiGate v v7.4.5 and above.
From v7.4.5 and above, FortiGate has three QUIC options within the SSL/SSH inspection profile:
config firewall ssl-ssh-profile
edit <name>
config https
set quic {inspect | bypass | block}
end
config dot
set quic {inspect | bypass | block}
end
next
end
Available options for the QUIC setting:
Observed behavior:
Browsers using experimental QUIC or DNS over QUIC (e.g., Cisco Umbrella Cloud Proxy) may experience:
Cause:
Recommendations:
To properly handle or block QUIC traffic under the new behavior:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.