Question
FQDN Addresses for Destination in a Policy
Hello I have a FortiGate running v4.0.0, build0092. I have been messing around for days now trying to make it allow my Trend Micro OfficeScan and ScanMail servers use the ActiveUpdate service without looking at the traffic at all. I have figured out how to make it work by creating a policy at the top of the list that allows HTTP to go unscanned, unprotected, all the time to an IP address for the Trend ActiveUpdate server (one of them...) but the problem now is that I noticed that the IP addresses that Trend uses for the servers are all dynamic (they change very quickly), I called Trend support and they confirmed that this is correct. I can get it to work by pinging the FQDN of each update server to get the current IPs then quickly going into the Fortigate and changing the IPs on the firewall addresses that are assigned to the policy and then quickly going into the Trend applications and forcing a manual server update. This you can imagine is not a solution. So I thought that I would just use the FQDNs in the firewall addresses for the policy. They don' t work, and I just can' t figure out why when I can ping them just fine. I will try to explain what I have set up and hopefully someone here may have some insight. Firewall Policy (at the top) internal -> wan1 Source: all Destination: Trend Update Servers (this is an address group) Schedule: always Service: HTTP Profile: None Action: ACCEPT Firewall Address 1 Name: Trend OS Update Server FQDN: osce8-p.activeupdate.trendmicro.com Interface: wan1 Firewall Address 2 Name: Trend SM Update Server 1 FQDN: smex8-as.activeupdate.trendmicro.com Interface: wan1 Firewall Address 3 Name: Trend SM Update Server 2 FQDN: smex8-p.activeupdate.trendmicro.com Interface: wan1 The above 3 addresses are grouped into the group name: Trend Update Servers As I mentioned above, this configuration doesn' t work, but, if I go into each address and change it to current IP instead of FQDN then everything works wonderfully, until the Trend IPs dynamically change (faster than you can blink). I would appreciate anyone' s help with this as I am now really frustrated. Thanks! Marc Jones
