Description | This article describes the impact of DNS server stability on validating the certificate chain while using the FortiProxy/FortiGate explicit proxy feature. |
Scope | FortiProxy, FortiGate, Explicit Proxy. |
Solution |
Configuration: FortiProxy is configured as an explicit proxy, and the certificate-inspection profile is in use:
Symptoms: The end user might face the issue, reporting that the browser observed that the certificate authority for well-known websites is being reported as invalid:
FortiProxy certificate is being presented when the end user attempts to access the well-known webpages:
Basic troubleshooting on FortiProxy indicates that Internet access is healthy:
Troubleshooting: It is possible to enable debugging to check on the issue:
diagnose debug console timestamp enable diagnose debug application fnbamd -1 diagnose wad filter src <user_IP> diagnose wad debug enable level verbose diagnose wad debug enable category all diagnose debug enable
If the following is being observed, this means that there is an issue with the DNS server's reachability:
[I]2025-08-03 19:39:41.988243 [p:4445] wad_dns_parse_name_resp :205 0: DNS response received for remote host a.clarity.ms req-id=0 ipv4=1 HTTP/1.1 200 Connection established
Further verification on the FortiProxy indicates that the DNS servers haven't been reachable:
It is worth noting that the behavior can be intermittent if the DNS server's reachability is intermittent. The end user might be observing the certificate error prompt while accessing Outlook App, or browsing a well-known website, but it resolves with refreshing the page without any changes made to the proxy policy.
It has been confirmed that DNS server stability is important when validating a web server certificate. Inability of the DNS server to resolve the FQDN will lead to certificate validation failure due to the proxy server is unable to retrieve the certificate chain or OSCP.
The main reason is that the certificate specified in certificate-inspection does not import to the user's browser. To display an error message when FortiProxy has an issue connecting to the DNS Server, it has to import the certificate into to user's browser. Any error messages can be displayed properly to the user's browser (sample screenshots) whenever the Explicit Proxy Service faces DNS issue, block page an etc.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.