Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
IrbkOrrum
Contributor

Issue with gracefully blocking iCloud Private Relay

I'm following the directions found here

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-iCloud-Private-Relay-from-byp...

Which are supposed to allow you to block the iCloud private relay but in a somewhat graceful way.  Meaning that the iPhone user should still be able to use their device, it's just not going to route traffic through the private relay.  However, when I follow the directions above the iphone basically stops any internet traffic saying "can't connect to iCloud Private Relay" until I manually turn off the private relay.  I've followed the directions but they don't seem to want to work as intended.

12 REPLIES 12
teddyb
New Contributor II

Hi @bwsitadmin 

 

I don't block proxy/vpn apps and I do explicitly block QUIC.  For the rest my setup is similar to yours.

 

What I had to do with DNS: I created two external servers running unbound (under Debian), modified DHCP scope to include them in the lease, and return NXDOMAIN for the following domains:

 

mask.icloud.com
mask-h2.icloud.com
mask.apple-dns.net
mask-api.fe.apple-dns.net
mask-t.apple-dns.net
gateway.fe2.apple-dns.net
apple-relay.cloudflare.com

 

With this setup I get Private Relay Unavailable message almost immediately.

 

Hope it helps.

garci66
New Contributor

In my case, I was able to the NXDOMAIN by editing the DNS filter options to return NXDOMAIN.. so that part works. And I'm blocking Proxys / VPNs. But the weird thing is that only on iphones, as soon as I was blocking QUIC via the app profile, a lot of google apps would stop working.  I know the google apps (like search, youtube or some pages in chrome) might not be 100% related, but it was happening only on iphones and not on any other device, so not sure if private relay not-completely-blocked was causing extra issues or what.  

 

Thanks for the datapoint though... 

zalonta1
New Contributor

I had it go on and off about three times in an hour on all of my devices. Since the last time it came back on, it has not happened again on any device.

router login 192.168.l.l
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors