FQDN address object just resolves ipv4 - no dual-stack - Any solutions?
Hello,
we write the year 2021 and ipv6 has grown to an over 30 years old protocol. But it still seems to lack basic support.
We switched from OPNsense to FortiGate and our network is dual-stacked. With OPNsense it was no problem to declare FQDN address objects that resolved to all A and AAAA records. And really nobody wants to create ipv6 objects manually. So we use mainly FQDN to access ipv6 resources.
In FortiGate FQDN objects just resolve to A records and no chance to get my ipv6 addresses added. Any hints, tricks how to keep our system dual-stacked without abandoning our ipv6 design or manually add each ip resource twice? The lack of ipv6 support makes many cool features useless e.g. FSSO agent. I bet users in ipv6 networks won't be resolved dynamically to address objects and get no access - except they disable ipv6 on their pcs.
How do you work with dual-stacked servers without adding everything twice and manually adding 128-bit long addresses which are more likely to have typos than legacy ips?
Kind regards,
Florian
