An event on a FortiGate device may be marked as "Unhandled" if a DNS request has been redirected to a block portal, because the device may not have a way to handle the redirection or may not recognize it as a valid response to the DNS request.
When a FortiGate device receives a DNS request, it checks its DNS cache to see if it already has a record of the requested domain name. If the domain name is not in the cache, the FortiGate device sends a DNS query to the configured DNS server. If the DNS server responds with a valid IP address, the FortiGate device will use that IP address to allow or block access to the requested resource.
However, if the DNS server responds with a redirection to a block portal, the FortiGate device may not recognize the response as a valid response to the DNS query. In this case, the FortiGate device may mark the event as "Unhandled" and take no further action.