Skip to main content
FortiZiq
Staff
Staff
October 29, 2024

Troubleshooting Tip: Why Wildcard FQDN or Wildcard FQDN Group Objects Cannot be Used in Policies in FortiManager

  • October 29, 2024
  • 0 replies
  • 1340 views
Description

This article describes why Wildcard FQDN objects are not configurable in policies in FortiManager.

Scope FortiManager.
Solution

Example Scenario:

The following firewall objects are created within FortiManager, an Address object, a Wildcard FQDN object, and a Wildcard FQDN Group object.

 

objects.png

 

When configuring policies in the Policy Package within FortiManager, notice that for the Source and Destination field, the Address object can be configured, but not the Wildcard FQDN or Wildcard FQDN Group objects.

 

policy_config.png

 

This is because Wildcard FQDN objects are only used for SSL/SSH Inspection Security Profile as shown below.

 

ssl_profile.png

 

To configure policies with wildcard FQDN, an address object must be created with the Category set as Address, and the Type set to FQDN. An example of a wildcard FQDN object that can be used in policies is shown below.

 

wildcard_address.png

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!