Description | This article describes why FortiGate is forwarding DNS queries for blocking or banning domains to the DNS servers. |
Scope | FortiGate DNS. |
Solution |
There are instances that the FortiGate is sending DNS queries to the configured DNS servers for a block or ban domain.
In this example, from the packet sniffer, it s possible to see that the FortiGate is querying the DNS server 10.201.2.41 for bansite.com.
Below is the FortiGate DNS setting:
Below is the Wireshark output:
This is an expected behavior if a FQDN address object has been configured in the firewall.
The FortiGate will query the DNS server to resolve the configured FQDN. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.