Hi, Did anyone faced an issue were suddenly Windows devices were sending big amount of DNS traffic to Actve Directory - which eventually leads to conserve mode on FortiGate device, We reach like 300k sessnions.. I heard that Windows has weird behaviour where there is a DNS high latency - then Windows is starting "flood" dns requests for whatever reason.. Im no sure if its true, but I dont see any other reason. Of cousrse there is no DDoS or any other malicious thing :)
Im starting to thinking that 200E maight be not enough for such amount of traffic, but its not explainging why Windows is behaving like this - I met this scenerio a few time in different companies as well.
FortiOS: 7.0.14
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
How do you know conserve mode is related to high amounts of DNS traffic? Does that traffic from the endpoints to AD even cross the 200E?
Hi Sanda
Yes I saw the same issue few months ago on a FG 1800F FOS 7.0.12.
We did the following to fix it:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.