Created on 04-29-2022 08:05 AM Edited on 04-29-2022 08:38 AM By Anthony_E
Description | This article aims to describe the recent changes in SDNS and Webfilter lookups, and also provide some tips on checking DNS and Webfilter categories on the FortiGate. |
Scope | All FortiOS versions. |
Solution |
SDNS and Webfilter lookups on the FortiGuard website have been updated to provide more granular lookup results based on the FortiOS version of the FortiGate - 7.0+, 5.6+, 5.4 or older.
The lookups are useful when troubleshooting why a specific website is getting blocked or when configuring DNS and Webfilter profiles.
SDNS lookup: www.fortiguard.com/services/sdns
Webfilter lookup: www.fortiguard.com/webfilter
In general, DNS and Webfilter categories for a specific website should be always the same for a given FortiOS version. In case there is a discrepancy, always submit a recategorization request:
In CLI check the category numbers with the following command:
#get webfilter categories <output omitted>
After the DNS filter to a forward traffic policy on the FortiGate, check the SDNS cache (list of saved hostnames and their SDNS categories) with the following CLI command:
# diagnose test application dnsproxy 15 worker idx: 0
For troubleshooting purposes, the SDNS cache can be cleared:
# diagnose test application dnsproxy 16
For more information on checking Webfilter cache please refer to the following article:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.