Description | This article describes how to check if FortiGuard DNS servers are sending EDNS Client Subnet (ECS) information in their queries. |
Scope | FortiGate v5.X, v6.X and v7.X. |
Solution |
Normal DNS queries are small, under 512 bytes, and can be accommodated in small UDP packets. EDNS allows us to send DNS data in bigger size packets over UDP. Both DNS server and network environment must be able to support bigger packet size and numerous fragments.
It is possible to check using DIG in Linux. As an example: dig @8.8.8.8 +subnet=74.123.206.0/24 www.google.com It is possible to change 8.8.8.8 to FortiGuard Server IP.
For Windows-related commands, follow the below link: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.