Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Daagvandermeer
New Contributor III

FG - Block ALL internet except DNS https://vbr.butler.veeam.com/

Is there a way to Block all Internet traffic except Veeam Malware detection URL?

The DNS is changing every time (IP's) so based on IPaddress Its not working always.

And I also created a DNS filter 

 
 

image.png

But I see still traffic to others based on IP (I think)

 

Is there another way to fix this?

 

Kind regards

Daag

2 Solutions
AEK
SuperUser
SuperUser

Are you using deep inspection? If so then it seems the internal server is not trusting the signing CA on FG.

 
AEK

View solution in original post

AEK
Daagvandermeer
New Contributor III

Thanks, I changed the SSL inspection to No Inspection. And that fixed it.
image.png

View solution in original post

12 REPLIES 12
Jean-Philippe_P
Moderator
Moderator

Hello Daagvandermeer, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
AEK
SuperUser
SuperUser

DNS filter may not work in such case because clients can access some locations without any DNS query.

Try use Web filter instead.

AEK
AEK
Daagvandermeer
New Contributor III

Thanks,

Now I tried.

image.png

 

But when I'm opening the website on the specific Server, Ill get Certificate errors.
(cant validate the certificate...)image.png

AEK

butler.veeam.com doesn't exist. Can you try open vbr.butler.veeam.com?

AEK
AEK
Daagvandermeer
New Contributor III

My mistake, here is the full url.
image.png

AEK

Please share the cert error on the browser, and the Web filter profile.

AEK
AEK
Daagvandermeer
New Contributor III

here is the Webfilter: image.png
and here is the screenshot on the server.
image.png

 

 

AEK
SuperUser
SuperUser

Are you using deep inspection? If so then it seems the internal server is not trusting the signing CA on FG.

 
AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors