Hello all,
the webfiltering profiles work good. it is ok. But, when the user changes dns ip on pc, her/his pc does bypass webfiltering.
For ex. twitter.com blocked in wf profile. Internal network get dhcp and dhcp is fg. Dns server 10.0.0.5.
When the pc take a ip address from dhcp and dns 10.0.0.5, twitter.com is blocked. it is good.
But, the user changer dns ip for ex. 8.8.8.8, twitter.com is passtroughed.
How can i block this situation?
Thanks.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Please a firewall rule that retsrict DNS to the set of DNS-namservers that you allow. Run diag debug flow on the client and google-dns and see what fw-policy is being hit.
e.g
diag debug disable
diag debug reset
diag debug flow filter addr 8.8.8.8
diag debug flow show console enable
diag debug flow trace start 100
diag debug enable
And then have the machine with the google-public dns start up a webrowser and see the fwpolicy that leaked thru DNS.
After your done, disable the diagnostic function.
diag debug reset
diag debug disable
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.