I am following https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-iCloud-Private-Relay-from-byp... to block iCloud private relay from bypassing the security inspection. My question come into the DNS filter portion of the guide. Since I do not user the DNS filter option in my FortiGates, I just create DNS policies on my internal Windows DNS servers to DENY (provides a response and not a drop) those domains. This brings up the bigger question for me of, Apple's own admission is that the only two domains needing to be set with "no error no answer" or at least some response...just not dropped, is mask.icloud.com and mask-h2.icloud.com. The linked guide however, adds several other domains to this beyond what Apple states, so just wondering about the discrepancy between Apple and Fortinet?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
i would say Fortinet's documentation is more detailed and exhaustive as it covers off all possible ways to block the traffic. If someone can bypass the DNS server then the web filter will block.
I would think Fortinet's documentation to block is is the one to follow. Apple's documentation may be talking about bare minimum for functionality. Can you post the Apple documentation you are referencing?
Sure, it's this link that was referenced (at the bottom) in the tech tip link I referred to in my question.
https://developer.apple.com/support/prepare-your-network-for-icloud-private-relay
i would say Fortinet's documentation is more detailed and exhaustive as it covers off all possible ways to block the traffic. If someone can bypass the DNS server then the web filter will block.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1517 | |
1013 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.