Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tutek
Contributor

No connection to DNS Filter Rating servers

Hello,

how could I troubleshoot dns filter rating servers unreachable?:

Tutek_0-1669795104335.png

 

5 REPLIES 5
lmarinovic
Staff
Staff

Hello Tutek,

 

Can you take a look at this KB:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-DNS-Filter-Rating-Servers-Unreachable-when...

 

Also here you can find Troubleshooting for DNS filter:

 

https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/150448/troubleshooting-for-d...

 

Best regards,

 

Lazar

 

 

Best regards

Lazar Marinovic
Tutek
Contributor

Hello,

I don't have dns over tls configured.

This is weird on dns pane I have access to dns servers (they list green):

208.91.112.53 30 ms
208.91.112.52 30 ms

 

but DNS Filter Rating Servers
173.243.140.53 Unreachable
173.243.142.53 Unreachable

droktor
New Contributor II

Guess is a matter of licensing, you are expired, remember this product is subscription based. Fortinet wants to bill you by every single option, soon they'll even bill you the DHCP option, so that's why it's failing to you.

 

mgoswami
Staff
Staff

Hi,

 

You would need to have a Web-Filtering license for this. If you already have a web-Filter license, please try these commands if you have not tried and see if it works:

config system fortiguard
set fortiguard-anycast disable
set protocol udp
set port 53
end

 

Regards,

Manosh

tthrilok
Staff
Staff

Hi Tutek,

 

Could you try the below commands:

 config system fortiguard
set sdns-server-ip "208.91.112.220"

end

Let us know if the above works.

Labels
Top Kudoed Authors