Basically, the request has to pass through a firewall policy. If it
passes through another VDOM, it will have to pass through another policy
and DNS filter can be applied. If it goes out directly to the internet
from the VDOM it will not have to matc...
Firstly, i cannot comment precisely on why something is a feature or
not. I believe the scenario you refer to would be possible with a
workaround. 1 example would be to use a second VDOM for the DNS
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.