Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ping out no DNS out?
Ive seen this issue a couple times, where users behind a Fortigate can ping, but suddenly cannot surf web as if DNS is not resolving. I know DNS is fine, and the Fortigate is reachable remotely.
Once the Fortigate is recycled, browsing is fine. I' m assuming it' s a proxy problem, any ideas?
15 REPLIES 15
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
it' s very difficult answer or help if posted in such terms.
Please, provide your FTG' s relevant settings , even a network diagram could helps.
regards
regards
/ Abel
regards
/ Abel
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
it' s very difficult answer or help if posted in such terms. Please, provide your FTG' s relevant settings , even a network diagram could helps.There are (3) PC' s behind the Fortigate 30b. This has happened twice in 3 days. I have two fw policies. One for HTTP&HTTPS which UTM is defined for blocking malware/greyware. And a Second policy for everything else...that' s it.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Double check your application control logs.
We have seen that sometime DNS requests are being blocked because the application control or IPS thinks it' s an attack.
-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Double check your application control logs. We have seen that sometime DNS requests are being blocked because the application control or IPS thinks it' s an attack.I don' t have any IPS settings enabled.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had a FWF30 and we had the exact same thing. I believe this is somehting else related but to the firewall or hardware. In our cases, it was the same 2-4 machines, you can ping out but for some reason hosts can' t resolve any dns-names.
I never open a ticket with fortigate, since I gave that unit away to a an associate of mine that had the exact same problems. he too like me, never investigated any time in trying to figure it out.
PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are users set to use the fortigate as a dns server? I am beginning to notice a similar problem with some of my locations as well.
With the 3.x firmwares, I noticed an issue with dns not resolving after the unit had been active for about 2 months without reboot. I' ve got 4.1.8 and 4.2.6 in all my locations and I' m noticing this problem again but only after about a day or two of uptime. If users set dns to an external server, dns seems to work fine, but the fortigate would stop forwarding dns requests sent to it directly.
I haven' t been able to pinpoint more details yet, the problem only began to pop up in a few locations yesterday. I' ve been using the 4.1.8 since december and started updating some sites to 4.2.6 when it came out a short time ago- strangely no problems of this nature until yesterday.
CISSP, NSE4
CISSP, NSE4
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are users set to use the Fortigate as a dns server? I am beginning to notice a similar problem with some of my locations as well.No, I am using two OPEN type DNS services such as, 208.67.222.222 & 8.8.8.8. One thing I noticed on a type of cablemodem specifically the Motorola Surfboard 6120 on two separate cable carriers (Comcast & TimeWarner). If I administratively take down the WAN interface and bring it back up, it starts working again?
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How about traffic shaping? After further prodding, the devices that are having dns resolution problems also have traffic shaping enabled in their internet access rules. Surprisingly other devices behind the same fortigate that are not subject to traffic shaping do not have any problems at the exact same time.
I too have no IPS enabled on the devices that experiencing problems.
CISSP, NSE4
CISSP, NSE4

Not applicable
Created on ‎07-13-2011 11:09 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Same issues with FG 60 models. If I uncheck " protection profiles" under the policy that allows users out to the internet, users will be able to surf.
I do not want to " Uncheck Protection Profiles" so I resboot and all works for a day or 2 and then Internet breaks again.
Any ideas ?
