Technical Tip: Wildcard FQDN may not sync with HA on FortiGate
| Description | This article describes the possible reasons why FortiGate may fail to synchronize wildcard FQDNs between HA FortiGates after the Secondary FortiGate is rebooted. |
| Scope | FortiGate less than v7.6.4. |
| Solution | Even after the Secondary FortiGate is rebooted and completes synchronization with the Primary FortiGate, the resolved IP address of the 'wildcard FQDNs' may not be synchronized.
In contrast, regular (non-wildcard) FQDNs are properly synchronized between the Primary and Secondary FortiGate.
Additionally, when the Primary FortiGate resolves a new IP address for a previously unsynchronized wildcard FQDN, that FQDN will subsequently be included in the synchronization process.
To confirm whether synchronization is taking place, run the following command via the CLI and compare the results between the Primary and Secondary FortiGate:
diagnose test application dnsproxy 6
The following shows the FQDN synchronization status after the Secondary FortiGate has been rebooted and HA synchronization has completed.
FG2600F-Primary (global) # diagnose test application dnsproxy 6
Secondary:
FG2600F-Secondary (global) # diagnose test application dnsproxy 6
Related documents: |
