Hello,
We have a fortigate FortiGate v6.4.11 running in our dependencies, and we try to block any connection to botnet C&C
We've got a policy with 2 Security Profiles:
When I use nslookup command to request an imaginary FQDN on a well-known malicious DNS server, Fortigate unexpectedly allows the request:
On the other hand, other fields make think the request should not reach the malicious server
So the thing is that ApplicationControl allows DNS network service, but DNS should block it since it is directed to a known malicious server.
To my understanding, communication should be blocked.
I have read the administration guide but I see no clue.
Did anyone face that problem before?
Thanks for your help,
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
To my knowledge DNS server doesn't validate the DNS Server itself just the DNS request as long as it's not HTTPS. If the domain requested is not matching any of those categories it should allow it.
You probably need to adjust your IPS filter to block access to the server itself.
To my knowledge DNS server doesn't validate the DNS Server itself just the DNS request as long as it's not HTTPS. If the domain requested is not matching any of those categories it should allow it.
You probably need to adjust your IPS filter to block access to the server itself.
Thanks for your clarification.
Am I right if I say the following?
One tool complements the other, and both must be implemented to contain outgoing botnet communication.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1702 | |
1092 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.