Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

Unreachable dns servers

Hi

 

I encountered a wired situation. When I enable web filter and dns filter in a policy, the dns servers on fortigate become unreachable or with high ping times and fortigate won't update at specified time. when i disable those security profiles the dns will have normal ping time. How can i solve this issue? I have tested with so many dns servers.

Reza F.
Reza F.
1 Solution
Bjay_Prakash_Ghising
Contributor

Hi rezafathi

 

A possible issue could be of large payload used. Please find the attached article.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-DNS-server-on-FortiGate-caused-FortiGate-D...

 

You may configure the appropriate setting considering the environment you have set.

 

Hope that helps, 

 

Kind Regards, 

Bijay Prakash Ghising

 

Ghising

View solution in original post

Ghising
2 REPLIES 2
AEK
Honored Contributor

Hello

Run a nslookup from FGT's CLI and share how long it takes to get the answer.

AEK
AEK
Bjay_Prakash_Ghising
Contributor

Hi rezafathi

 

A possible issue could be of large payload used. Please find the attached article.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-DNS-server-on-FortiGate-caused-FortiGate-D...

 

You may configure the appropriate setting considering the environment you have set.

 

Hope that helps, 

 

Kind Regards, 

Bijay Prakash Ghising

 

Ghising
Ghising
Labels
Top Kudoed Authors