Created on
07-18-2019
12:51 AM
Edited on
12-28-2022
11:42 AM
By
jheadley_FTNT
Description
FortiOS DNS filter unable to control encrypted DNS traffic
Severity : 3 - Medium
Acknowledgement : Fortinet thank John Headley from VPLS Solutions bring this issue to our attention with certain proofs.
Scope
Solution
Upgrade to FortiOS 7.0.x or later. More details on the new DoH/DoT support in DNS Filter can be read here.
Workaround:
Prevent DNS over HTTPS and DNS over TLS remote services.
In order to do that, FortiOS administrators may block the TLS (generally TCP port 853) and HTTPS (generally TCP port 443) traffic to publicly known DoT/DoH service providers, using FortiOS firewall policies.
Note: Another strategy is using Web filter policies instead of DNS filtering to perform website or URL access control.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.