Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SCHMIEDER_Operator
New Contributor

DNS Security Profile blocks safe domains

 Why the DNS Security Profile Blocks Domains that are safe, 

how does the DNS profile marks a domain as unsafe?
FortiGate 

4 REPLIES 4
adambomb1219
SuperUser
SuperUser

It gets its data from FortiGuard.  More importantly though what categories do you have allowed/blocked in the DNS inspection profile?

Keerthi_A
Staff
Staff

Hi @SCHMIEDER_Operator ,

 

You may go through the below link to view under which category the respective domain is categorized

 

https://www.fortiguard.com/services/sdns

 

If you believe the domain is wrongly categorized, please raise a case with Fortinet support for further analysis.

 

If the domain is rightly categorized, and you have allowed the category in dns filter, but still the domain is blocked, could you share the dns profile you are referring to and also the dns filter logs.

 

-AK

hbac
Staff
Staff

Hi @SCHMIEDER_Operator,

 

It depends on the category of the domain and the action set under the DNS filter. You can follow this article to whitelist it: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Static-DNS-filter-to-allow-block-DNS-queri...

 

Regards, 

Nchandan
Staff
Staff

The DNS Security Profile aims to strike a balance between security and accessibility. While it can occasionally block safe domains due to the factors Categorization Errors, Dynamic Content, False Positives, and Algorithmic Analysis, it's a valuable tool in protecting your network from potentially malicious or unsafe content. Regularly reviewing and fine-tuning your configuration can help ensure that it works effectively while minimizing false positives.

Labels
Top Kudoed Authors