DNS traffic in NGFW mode
Certain Application Control profiles might not work properly if DNS traffic is not allowed. You can enable the implicit-allow-dns
option to add an implicit policy allowing DNS traffic. This policy is situated in the policy sequence just above the implicit deny policy.
CLI
config system settings
set implicit-allow-dns {enable|disable}
end