Helpful ReplyHot!DNS Requests -> Forwarding Proxy

Author
connect555
Bronze Member
  • Total Posts : 26
  • Scores: 0
  • Reward points: 0
  • Joined: 2009/06/19 00:24:15
  • Status: offline
2016/02/04 00:24:24 (permalink)
0

DNS Requests -> Forwarding Proxy

Hi, we´re switching from MS FTMG to FortiGate with Explicit Web Proxy and a "Web Proxy Forwarding Server". The MS FTMG sends all DNS-Request to the configured 'Upstream Proxy'. How can i configure this Option on a FortiGate? Opening a Website results in '504 DNS look up failed'. Using a local DNS-Server is not an Option. There is no Webfilter configured.
#1
40netter
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/02/01 05:12:42
  • Status: offline
Re: DNS Requests -> Forwarding Proxy 2018/02/01 05:16:07 (permalink)
0
Does anybody have a solution to this. We have the exact same problem here.

Even though the requests are meant to be forwarded to the parent proxies it seems like the Fortigate tries to do dns resolution on the hostnames, which, ofcourse, fails since the internal DNS server only knows about names in the lan.

Any way of disabling dns resolution when forwarding requests would be really helpful.
#2
pavol.jaco@gmail.com
New Member
  • Total Posts : 4
  • Scores: 2
  • Reward points: 0
  • Joined: 2018/09/19 23:53:38
  • Status: offline
Re: DNS Requests -> Forwarding Proxy 2018/09/20 00:00:29 (permalink) ☄ Helpfulby connect555 2018/10/23 23:22:56
5 (1)
I have opened ticket for this problem. Guess what... it is normal and as per design :)
Of coarse this is absolutely wrong design. You dont need to resolve anything via DNS when using proxy. As support said, this is simply not yet implemented feature in FortiOS.
#3
connect555
Bronze Member
  • Total Posts : 26
  • Scores: 0
  • Reward points: 0
  • Joined: 2009/06/19 00:24:15
  • Status: offline
Re: DNS Requests -> Forwarding Proxy 2019/04/22 13:23:27 (permalink)
0
Any update to this behavior?
FortiOS 6.2? mhmh?
#4
sw2090
Gold Member
  • Total Posts : 312
  • Scores: 20
  • Reward points: 0
  • Joined: 2017/06/14 01:27:25
  • Location: Regensburg
  • Status: offline
Re: DNS Requests -> Forwarding Proxy 2019/04/24 06:32:33 (permalink)
0
hm you could to two things:
 
a) set the FGT system DNS to your DNS Proxy. Enable DNS Databse Feature on your FGT and configure a DNS Forwarder on the FGT for the interface you need on.
b) let DHCP do it for you. Letzt the FGT be DHCP Server on the interface you need and set the DHCP Server to hand out the proxy as DNS to the Clients.
#5
Jump to:
© 2019 APG vNext Commercial Version 5.5