Created on
06-27-2025
09:57 AM
Edited on
06-29-2025
12:29 PM
By
Jean-Philippe_P
Description |
This article describes a behavior where users can not ping any domain from FortiGate and FortiGuard communication do not works for Upgrades or rating. |
Scope | FortiGate with DNS server configuration. |
Solution |
In some cases, users are unable to connect to FortiGuard from FortiGate.
On the FortiGate, it is not possible to ping google.com, but pinging 8.8.8.8 is working.
Run the following DNS debug commands:
diagnose debug application dnsproxy -1 diagnose debug enable
In the debugs, the following error will be visible:
[worker 0] dns_server_setup()-431: ip=96.45.46.46 encrypt=none rating=0 d[worker 0] dns_policy_load_vd()-2948: vdom=root
[worker 0] dns_profile_load_vd()-2542: vfid=0
[worker 0] dns_url_table_load_vd()-2705: vfid=0
[worker 0] vdom_info_reinstall_dns_settings()-804: vdinfo=root
Restarting the dnsproxy daemon does not work.
Solution:
Increase the DNSProxy engine count:
config system global
After applying this configuration, verify that pinging google.com and FortiGuard services work again. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.