Hello All,
On our FortiGates under Global/Network/DNS we specify our own DNS Servers but they are almost always in red (high latency) or showing as unreachable.
We are only using plain old DNS (udp/53).
We have never been able to work out why (it happens on both our 600F and 100F) and what we need to do to fix it , I have no idea if there is some config somewhere that's missing etc etc.
Hoping the experts out there can help ?
Regards
Hi
Is you DNS resolution fine when you send the query to the configured DNS servers?
Does you FGT resolve in acceptable time?
We are having the exact same issue. Did you manage to resolve it?
Hi @gokiwi64
To address the issue of high latency or unreachable DNS servers on your FortiGate devices, follow these steps:
1. Ensure that the DNS servers specified are correct and reachable from the FortiGate. 
You can use the "# exec ping" command to test connectivity to the DNS servers
2. Since you are using plain DNS (UDP/53), ensure that DNS over TLS or DNS over HTTPS is not enabled, as these require different ports (TCP/853 for DoT and TCP/443 for DoH).
3. Use the command " # diagnose test application dnsproxy 2 "to check the latency and status of the DNS servers.
This will provide insights into whether the servers are responding slowly or not at all.
Best regards,
Erlin
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2711 | |
| 1416 | |
| 810 | |
| 727 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.