DNS filter handled by IPS engine in flow mode
In FortiOS 6.4, the DNS proxy daemon handles the DNS filter in flow and proxy mode policies. Starting in 7.0, the IPS engine handles the DNS filter in flow mode policies and queries the FortiGuard web filter server for FortiGuard categories. In proxy mode, the DNS proxy daemon handles the DNS filter and queries the FortiGuard SDNS server for FortiGuard categories.
All features previously supported in the DNS filter profile are supported in flow mode:
- FortiGuard category rating
- Static domain filtering
- Remote category rating
- External IP block list
- Botnet domain and IP filtering
- DNS translation
- Safe search enforcement
![]() |
When a DNS filter profile is enabled in |