Regards, Chris McMullan Fortinet Ottawa
I have tried to program that exact solution on the DNS on the FortiGate but it does not work. Just wondering if anyone has actually done it.Hello You can' t do a CNAME for domain name of the zone. You need to create a A record for " www.google.com -> 216.239.32.20" See attached file
config firewall dnstranslation edit 1 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.97 next edit 2 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.96 next edit 3 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.110 next edit 4 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.100 next edit 5 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.104 next edit 6 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.99 next edit 7 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.101 next edit 8 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.113 next edit 9 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.116 next edit 10 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.112 next edit 11 set dst 216.239.32.20 set netmask 255.255.255.255 set src 173.194.43.115 next endAs I stated, I did this for kicks -- works " great" on a 200D (that' s on my work bench), providing the source IP is in the table. Can' t see anyone wanting to do this with Google' s IP pool. @dasilva13 Re: installing host file on 1500+ laptops Some of the companies I' ve worked at actually did this via policies and/or login scripts.
I have tried to program that exact solution on the DNS on the FortiGate but it does not work. Just wondering if anyone has actually done it.When testing out the proposed DNS solution(s) offered here, make sure you flush the DNS resolver cache on your test machine(s). You may also want to set up fw polices on the fgt to prevent client machines from directly accessing outside DNS servers.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Some point in early December Google are turning off the nossl option.
http://googleonlinesecurity.blogspot.com.au/2014/10/an-update-to-safesearch-options-for.html
The new option will force the use of SSL.
https://support.google.com/websearch/answer/186669
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.