FortiGuard DNS Rating Server (SDNS) unavailable

Last update from 12.05.2021 at 09:40 Swiss local time: We have noticed an improvement in the situation. Some rare rating timeouts still show up from time to time, but the majority of requests are being answered correctly. Also the DNS servers are working as usual again.

We have noticed an increase of support requests regarding the FortiGuard DNS rating service (SDNS) today. Therefore we want to inform you about the following issue.

The FortiGuard SDNS servers are not available as usual at the moment. This problem concerns at least fortiOS 6.0, 6.2, 6.4 and 7.0. You can confirm this issue on your FortiGate by:

  • Check the «Webfilter» log for messages like «rating timeout», «A rating error occurs» or «all Fortiguard servers failed to respond» messages in the «error» column.
  • Check the «DNS Query» log for «no available FortiGuard SDNS servers» or «DNS query timeout» messages in the «error» column.

We have also noticed, that:

  • The command «diag debug rating» shows no problems.
  • The «Test Connectivity» Button under «System» and «FortiGuard» in the WebGUI does still indicate a normal functional state.
  • Some systems that are sized a little too small may run into performance issues.

At the moment we can recommend you the following workarounds:

  • Enable the option «Allow websites when a rating error occurs» in your Webfilter and DNS Filter profiles.

We will update this blog post as soon as we have any news to communicate.