DNS Proxy Debugging

Use these commands when clients using the FortiGate as DNS server receive wrong answers, slow responses, or no response.

Configuration checks

show system dns
show system dns-server
show system interface

Confirm the listening interface, DNS service setting, upstream DNS servers, and any local DNS database entries.

DNS proxy status

diagnose test application dnsproxy 1
diagnose test application dnsproxy 3

Enable DNS proxy debug

diagnose debug reset
diagnose debug console timestamp enable
diagnose debug application dnsproxy -1
diagnose debug enable

Stop the debug when finished:

diagnose debug disable
diagnose debug application dnsproxy 0
diagnose debug reset

Packet check

diagnose sniffer packet any 'port 53' 4 0 a