Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fb1907
New Contributor

dns for webfiltering

Hello all,

 

the webfiltering profiles work good. it is ok. But, when the user changes dns ip on pc, her/his pc does bypass webfiltering.

 

For ex. twitter.com blocked in wf profile. Internal network get dhcp and dhcp is fg. Dns server 10.0.0.5.

 

When the pc take a ip address from dhcp and dns 10.0.0.5, twitter.com is blocked. it is good.

 

But, the user changer dns ip for ex. 8.8.8.8, twitter.com is passtroughed.

 

How can i block this situation?

 

Thanks.

1 REPLY 1
emnoc
Esteemed Contributor III

Please a firewall rule that retsrict DNS  to the set of  DNS-namservers that you allow. Run diag debug flow on the  client and google-dns and see what fw-policy is being hit.

 

e.g

 

diag debug disable

diag debug reset

diag debug flow filter addr 8.8.8.8

diag debug flow show console enable

diag debug flow trace start 100

diag debug enable

 

And then have the machine with the google-public dns start up a webrowser and see the fwpolicy that leaked thru DNS.

 

After your done, disable the diagnostic function.

 

 

diag debug reset

diag debug disable

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors