Fortinet Document Library

Version:


Table of Contents

New Features

7.0.0
Download PDF
Copy Link

DNS filter handled by IPS engine in flow mode

In FortiOS 6.4, the DNS proxy daemon handles the DNS filter in flow and proxy mode policies. Starting in 7.0, the IPS engine handles the DNS filter in flow mode policies and queries the FortiGuard web filter server for FortiGuard categories. In proxy mode, the DNS proxy daemon handles the DNS filter and queries the FortiGuard SDNS server for FortiGuard categories.

All features previously supported in the DNS filter profile are supported in flow mode:

  • FortiGuard category rating
  • Static domain filtering
  • Remote category rating
  • External IP block list
  • Botnet domain and IP filtering
  • DNS translation
  • Safe search enforcement
Note

When a DNS filter profile is enabled in config system dns-server, the DNS proxy daemon handles the traffic.

DNS filter handled by IPS engine in flow mode

In FortiOS 6.4, the DNS proxy daemon handles the DNS filter in flow and proxy mode policies. Starting in 7.0, the IPS engine handles the DNS filter in flow mode policies and queries the FortiGuard web filter server for FortiGuard categories. In proxy mode, the DNS proxy daemon handles the DNS filter and queries the FortiGuard SDNS server for FortiGuard categories.

All features previously supported in the DNS filter profile are supported in flow mode:

  • FortiGuard category rating
  • Static domain filtering
  • Remote category rating
  • External IP block list
  • Botnet domain and IP filtering
  • DNS translation
  • Safe search enforcement
Note

When a DNS filter profile is enabled in config system dns-server, the DNS proxy daemon handles the traffic.