Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jtfinley
Contributor

Ping out no DNS out?

Ive seen this issue a couple times, where users behind a Fortigate can ping, but suddenly cannot surf web as if DNS is not resolving. I know DNS is fine, and the Fortigate is reachable remotely. Once the Fortigate is recycled, browsing is fine. I' m assuming it' s a proxy problem, any ideas?
15 REPLIES 15
abelio
SuperUser
SuperUser

Hi, it' s very difficult answer or help if posted in such terms. Please, provide your FTG' s relevant settings , even a network diagram could helps. regards

regards




/ Abel

regards / Abel
jtfinley

it' s very difficult answer or help if posted in such terms. Please, provide your FTG' s relevant settings , even a network diagram could helps.
There are (3) PC' s behind the Fortigate 30b. This has happened twice in 3 days. I have two fw policies. One for HTTP&HTTPS which UTM is defined for blocking malware/greyware. And a Second policy for everything else...that' s it.
ddskier
Contributor

Double check your application control logs. We have seen that sometime DNS requests are being blocked because the application control or IPS thinks it' s an attack.

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
jtfinley

Double check your application control logs. We have seen that sometime DNS requests are being blocked because the application control or IPS thinks it' s an attack.
I don' t have any IPS settings enabled.
emnoc
Esteemed Contributor III

I had a FWF30 and we had the exact same thing. I believe this is somehting else related but to the firewall or hardware. In our cases, it was the same 2-4 machines, you can ping out but for some reason hosts can' t resolve any dns-names. I never open a ticket with fortigate, since I gave that unit away to a an associate of mine that had the exact same problems. he too like me, never investigated any time in trying to figure it out.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Kenundrum
Contributor III

Are users set to use the fortigate as a dns server? I am beginning to notice a similar problem with some of my locations as well. With the 3.x firmwares, I noticed an issue with dns not resolving after the unit had been active for about 2 months without reboot. I' ve got 4.1.8 and 4.2.6 in all my locations and I' m noticing this problem again but only after about a day or two of uptime. If users set dns to an external server, dns seems to work fine, but the fortigate would stop forwarding dns requests sent to it directly. I haven' t been able to pinpoint more details yet, the problem only began to pop up in a few locations yesterday. I' ve been using the 4.1.8 since december and started updating some sites to 4.2.6 when it came out a short time ago- strangely no problems of this nature until yesterday.

CISSP, NSE4

 

CISSP, NSE4
jtfinley

Are users set to use the Fortigate as a dns server? I am beginning to notice a similar problem with some of my locations as well.
No, I am using two OPEN type DNS services such as, 208.67.222.222 & 8.8.8.8. One thing I noticed on a type of cablemodem specifically the Motorola Surfboard 6120 on two separate cable carriers (Comcast & TimeWarner). If I administratively take down the WAN interface and bring it back up, it starts working again?
Kenundrum
Contributor III

How about traffic shaping? After further prodding, the devices that are having dns resolution problems also have traffic shaping enabled in their internet access rules. Surprisingly other devices behind the same fortigate that are not subject to traffic shaping do not have any problems at the exact same time. I too have no IPS enabled on the devices that experiencing problems.

CISSP, NSE4

 

CISSP, NSE4
Not applicable

Same issues with FG 60 models. If I uncheck " protection profiles" under the policy that allows users out to the internet, users will be able to surf. I do not want to " Uncheck Protection Profiles" so I resboot and all works for a day or 2 and then Internet breaks again. Any ideas ?
Labels
Top Kudoed Authors