Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
luca1994
New Contributor III

Fortigate Manage BlackList

Hello team,

 

I wanted to know what is the best method to manage fqdn to be blacklisted. Basically, is it better to use an ad hoc web filter profile or to create fqnd groups with wildcards?

My goal is to block specific fqdn for everyone globally.

 

Thanks for the support
BR

1 Solution
AEK

Hello

Enable All traffic log in the related policy, then check in the traffic log. You should find there traffic log witch client IP as source, DNS server IP as destination, and DNS as protocol/service.

AEK

View solution in original post

AEK
14 REPLIES 14
luca1994
New Contributor III

Hello @hbac and thanks for the support.

how do i check if dns requests go through fortigate? with what commands?

 

i'm using fortios 7.4.6

 

Thanks

Br

AEK

Hello

Enable All traffic log in the related policy, then check in the traffic log. You should find there traffic log witch client IP as source, DNS server IP as destination, and DNS as protocol/service.

AEK
AEK
mle2802
Staff
Staff

Hi @luca1994.
Another solution you can consider is using threat feed to import a list of FQDN and use it as category for web filter.

Regards,
Minh

adimailig
Staff
Staff

If your concern is about HTTP/HTTPS traffic going to FQDN you can manage or block it using Web Filter.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-a-static-URL-filter-feature-to-allow...


Best Regards,

Arnold Dimailig
TAC Engineer
Labels
Top Kudoed Authors