| Description | This article describes how to use URL Match + Forward Server on FortiProxy to forward specific Explicit Web Proxy traffic to an upstream proxy without performing DNS resolution locally. |
| Scope | FortiProxy 7.4, FortiProxy 7.6. |
| Solution |
An internal FortiProxy receives traffic on an Explicit Proxy port but cannot resolve certain external hostnames. These requests must be forwarded to an upstream proxy that can perform DNS resolution.
When the requested URL matches a URL Match rule, FortiProxy:
If the URL does not match, FortiProxy attempts DNS resolution itself and may return an HTTP 504 DNS Timeout if resolution fails.
config web-proxy url-match
FortiProxy forwards matching requests to the upstream proxy without DNS checks, ensuring successful resolution and preventing DNS timeout errors. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.