Description | This article describes how to configure FortiProxy as a child proxy not to perform DNS Lookup for client HTTP requests of specific URL |
Scope | FortiProxy. |
Solution |
By default, in explicit proxy-chain setup, FortiProxy as child-proxy will perform DNS lookup for the intercepted client HTTP requests.
Example setup, FortiProxy (child-proxy) intercepts incoming HTTP requests from the user. It then forwards the HTTP request to FortiGate (parent-proxy).
Computer IP@: 10.100.3.119
FortiProxy will perform a DNS lookup on a client request. Refer to the packet capture screenshot below:
If one wants to exempt the URL from DNS lookup in FortiProxy (child-proxy), it is possible to do a 'Server URL' configuration, so that FortiProxy do not perform the DNS lookup on those URL, and let the parent proxy do it. The following configuration bypass URL "example.com" from DNS lookup on child-proxy.
config web-proxy url-match
With the Server URL configuration, the FortiProxy will not perform the DNS lookup on the URL that matches the Server URL setting. Refer to the packet capture screenshot below: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.