Hot!DNS Static URL Filter

Author
qweqwelani
New Member
  • Total Posts : 3
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/02/14 09:52:37
  • Status: offline
2018/02/14 10:15:42 (permalink)
0

DNS Static URL Filter

Hi,
I am trying setup fortigate (version 5.2) to block every DNS request except the requests querying for whitelisted domains.
 
I've setup fortigate unit to use FortiGuarde DNS servers and also use fortigate as my internal DNS server. Then I've created Web Filer policy to block everything but  DNS request to resolve google.com

 
I've applied this policy to firewall rules. But I am still able to resolve every domain.
What am I doing wrong? And is it even possible to achive my goal?
post edited by qweqwelani - 2018/02/14 23:51:17

Attached Image(s)

#1

3 Replies Related Threads

    Toshi Esumi
    Expert Member
    • Total Posts : 1170
    • Scores: 66
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: DNS Static URL Filter 2018/02/14 14:25:21 (permalink)
    0
    I haven't used DNS web filtering myself. But based on the online help description below:
    http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_DNSInspectionProfile.htm
    category filtering seems to be necessary.
    Try configure them in local categories instead of Static URL Filter to see if it works. If not, you probably need to open a case at TAC.
    #2
    qweqwelani
    New Member
    • Total Posts : 3
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/02/14 09:52:37
    • Status: offline
    Re: DNS Static URL Filter 2018/02/15 04:14:00 (permalink)
    0
    Unfortunately category filtering is not licensed for my device. I've tried it anyway, but without any luck.
    #3
    Toshi Esumi
    Expert Member
    • Total Posts : 1170
    • Scores: 66
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: DNS Static URL Filter 2018/02/15 08:39:50 (permalink)
    0
    Mostlikely at least that part of FortiGuard license/subscription is required. You can verify with a sales or TAC.
    #4
    Jump to:
    © 2018 APG vNext Commercial Version 5.5