Description
This article describes how to prevent users from accessing the internet if it is possible to access it by adjusting the DNS server IP on their devices even when in isolation or when connected to the guest network.
Scope
FortiNAC, FortiNAC-F.
Solution
If there are cases where the users can access the internet by changing their DNS server IP to 8.8.8.8, even when isolated or are trying to connect to the guest network. The below should be done to avoid such cases.
- Outbound DNS must be blocked except for the eth1/port 2 interface. The firewall rule should only allow DNS traffic to FortiNAC Eth1/port2 port.
See the below document for more details, page 57 onwards:
Deployment Guide FortiNAC 9.2.0
-
In the case that the users are smart enough to play around with free VPNs and proxies and use these to access the internet using devices, it is required that the Firewall is configured to block VPN as well from the Isolation network.