Description | This article describes the case when FortiSwitches show offline due to the dnsfilter-profile configuration. |
Scope | FortiGate and FortiSwitch versions 6.4.x, 7.0.x. |
Solution |
FortiSwitches may show offline on FortiGate after FortiGate or FortiSwitches reboot due to the below configuration on the FortiGate:
config system dns-server
Adding the DNS filter allows FortiGate to check the DNS queries (made by the FortiSwitch) against FortiGuard and block those that match a blocked category.
Solution: Remove dns-filter default profile in the DNS server config as it could block some capwap packets sent out of FortiGate.
config system dns-server |