Why does the firewall show “Category Query Fail-Open” even after changing DNS?

Options
Zyxel_Stanley
Zyxel_Stanley Posts: 1,481 image  Zyxel Employee
100 Answers 1000 Comments Friend Collector Eighth Anniversary

Question:
Why does the firewall show “Category Query Fail-Open” even after changing DNS?

Answer:
Please troubleshoot in this order:

  1. Check DNS settings: confirm the firewall can correctly resolve
    "gti-trellix.api.cloud.zyxel.com".
  2. Check server reachability: verify connectivity to "gti-trellix.api.cloud.zyxel.com".
  3. Check packet flow (both directions): confirm traffic is not only outbound but also has return packets (TCP handshake must complete).
    If outbound works but no return traffic, review upstream NAT/router security inspection/filtering and allow bi-directional traffic to/from the server.