Fortinet white logo
Fortinet white logo

CLI Reference

config dnsfilter profile

config dnsfilter profile

Description: Configure the DNS filter profile.

config dnsfilter profile
  edit <name>
    config domain-filter
      set domain-filter-table <name>
    end
    set block-action [block| redirect | block-servfail]
    set block-botnet [enable | disable]
    set safe-search [enable | disable]
    set youtube-restrict [strict | moderate]
    set redirect-portal {ipv4-address}
  next
end
Parametrer Description Type Size Default

block-action

Action to take for blocked domains.

option

-

Option

Description

block

The DNS request is blocked and a DNS response with NXDOMAIN is returned.

redirect

A DNS response containing the portal IP address is returned, redirecting blocked domains to the SDNS portal.

block-sevrfail

The DNS request is blocked, and a DNS response with SERVFAIL is returned.

block-botnet

Enable/disable blocking botnet C&C DNS lookups.

option

disabled

Option

Description

disable

Disable blocking botnet C&C DNS lookups.

enable

Enable blocking botnet C&C DNS lookups.

safe-search

Enable/disable Google, Bing, YouTube, Qwant, DuckDuckGo safe search.

option

disabled

Option

Description

disable

Disable Google, Bing, YouTube, Qwant, DuckDuckGo safe search.

enable

Enable to avoid explicit and inappropriate results in the Google, Bing, and YouTube search engines.

youtube-restrict

When safe-search is enabled, you can set safe search for YouTube restriction level.

option

disabled

Option

Description

strict

Enable strict safe search for YouTube.

This restricts YouTube access by responding to DNS resolutions with CNAME restrict.youtube.com.

moderate

Enable moderate safe search for YouTube.

This restricts YouTube access by responding to DNS resolutions with CNAME restrictmoderate.youtube.com.

redirect-portal

Enter the IP address of the SDNS redirect portal

ip-address

0.0.0.0

config domain filter
Parameter Description

Type

Size

Default

domain-filter

Configure the domain-filter-table parameter to apply a previously created domain filter to this profile.

table

-

domain-filter-table

Enter the domain filter name.

string

-

config dnsfilter profile

config dnsfilter profile

Description: Configure the DNS filter profile.

config dnsfilter profile
  edit <name>
    config domain-filter
      set domain-filter-table <name>
    end
    set block-action [block| redirect | block-servfail]
    set block-botnet [enable | disable]
    set safe-search [enable | disable]
    set youtube-restrict [strict | moderate]
    set redirect-portal {ipv4-address}
  next
end
Parametrer Description Type Size Default

block-action

Action to take for blocked domains.

option

-

Option

Description

block

The DNS request is blocked and a DNS response with NXDOMAIN is returned.

redirect

A DNS response containing the portal IP address is returned, redirecting blocked domains to the SDNS portal.

block-sevrfail

The DNS request is blocked, and a DNS response with SERVFAIL is returned.

block-botnet

Enable/disable blocking botnet C&C DNS lookups.

option

disabled

Option

Description

disable

Disable blocking botnet C&C DNS lookups.

enable

Enable blocking botnet C&C DNS lookups.

safe-search

Enable/disable Google, Bing, YouTube, Qwant, DuckDuckGo safe search.

option

disabled

Option

Description

disable

Disable Google, Bing, YouTube, Qwant, DuckDuckGo safe search.

enable

Enable to avoid explicit and inappropriate results in the Google, Bing, and YouTube search engines.

youtube-restrict

When safe-search is enabled, you can set safe search for YouTube restriction level.

option

disabled

Option

Description

strict

Enable strict safe search for YouTube.

This restricts YouTube access by responding to DNS resolutions with CNAME restrict.youtube.com.

moderate

Enable moderate safe search for YouTube.

This restricts YouTube access by responding to DNS resolutions with CNAME restrictmoderate.youtube.com.

redirect-portal

Enter the IP address of the SDNS redirect portal

ip-address

0.0.0.0

config domain filter
Parameter Description

Type

Size

Default

domain-filter

Configure the domain-filter-table parameter to apply a previously created domain filter to this profile.

table

-

domain-filter-table

Enter the domain filter name.

string

-