FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
JCPL
Staff
Staff
Article Id 342241
Description

This article describes how to fix an issue where the 'web page blocked!' message is displayed by FortiGate when using an internal DNS server.

 

DNS0.PNG

Scope FortiGate.
Solution

Topology:

 

DNS1.PNG

 

Context:

 

The computer has the internal DNS server configured as 192.168.1.20, as shown in the following image:

 

DNS2.PNG

 

Check website domain resolution via Command Prompt:

 

DNS3.PNG

 

The FQDN resolved to IP 208.91.112.55, which belongs to the FortiGuard default portal. Upon reviewing one of the DNS profiles, it was identified that this IP is associated with the Redirect portal. The blocking message appears because the DNS profile is responsible for the block.

The LAN to WAN firewall policy has DNS and Web filter security profiles.

 

DNS4.PNG

 

Below are the possible solutions for the scenario and problem raised:

  1. Run the command 'Clear-DnsServerCache' on the DNS server after production hours in the Windows DNS server.
  2. Create a new firewall policy allowing DNS service (port 53) from the DNS server IP to the Internet, without applying DNS security profiles. Place this new policy above the existing Internet firewall policy. The firewall policy should be structured as follows:

DNS5.PNG

 

  1. Allow the website from the DNS Profile using the Static Domain Filter

After the changes, users who have the Internal DNS server configured should not experience these types of blocks when consulting websites.

 

If disabling the DNS filter is not a feasible option, make sure that the category of the URL that is trying to resolve falls under the allowed/monitor category. More information is available in FortiGuard category-based DNS domain filtering.

 

To use an alternative block option like Return NXDOMAIN or SERVFAIL other than redirect to block portal refer to this article Technical Tip: Various Block option under DNS filter.

For more DNS filter troubleshooting assistance, refer to this document: Troubleshooting for DNS filter.

Comments
GILMENDO
Staff
Staff

Great article @JCPL thank you!

MaryBolano
Staff
Staff

Awesome @JCPL Juan Lewis, keep it up! 

lpedraza
Staff
Staff

Juan @JCPL , Team: Well done! We do appreciate your valuable contribution!