Troubleshooting Tip: FQDN Syslog is not working after the v7.4.8 upgrade
| Description | This article describes the issue that the FQDN syslog is not working after upgrading to FortiGate v7.4.8. |
| Scope | FortiGate v7.4, FortiGate v7.6. |
| Solution | As of version 7.4.8, FortiGate does not cache FQDNs when the DNS A record has a TTL (Time To Live) of 0.
Since no cache entry exists, FortiGate should send a DNS query for the syslog server FQDN each time before sending syslog when the TTL is 0.
To resolve the issue of FQDN syslog not working after upgrading to FortiGate v7.4.8, follow these steps:
If the TTL is verified to be 0, the FortiGate will not cache the resolved IP address and will not even send a syslog-related FQDN DNS query, and this behavior is confirmed as a bug.
It is also important to note that a DNS TTL value of 0 is not recommended, as it can cause increased DNS traffic and higher server load. For a logging server, this can result in each log delivery triggering a DNS query to the DNS server, which can cause performance issues and unreliability.
Note: This issue has been fixed in FortiGate v8.0.0. |
