Created on
07-31-2022
09:46 PM
Edited on
05-27-2025
09:53 PM
By
Anthony_E
Description | The article describes how to solve the high latency when a FortiGuard DNS server is used. |
Scope |
FortiGate. |
Solution |
Starting from firmware v7.0 onwards, the 'Use FortiGuard Servers' DNS will be using DNS over TLS by default, but some of the sites will have high latency even unreachable to FortiGuard DNS.
Note: In some cases, it shows high latency or unreachable, as some known DNS servers don't support DNS over TLS. Some Internet Service Providers (ISPs) still use traditional DNS without encryption.
The DNS Protocols will be greyed out on GUI as shown below:
To change the different methods to reach FortiGuard DNS, for example, change default TLS(TCP/853) to DNS (UDP/53), it is possible to change using the CLI command below:
config system dns end
Note: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.