Skip to main content
Mahmood_Fraidoon
New Member
January 22, 2014
Question

Policy based on specific URLs

  • January 22, 2014
  • 9 replies
  • 15134 views
Hello I was wondering if I can create a objects based on URL instead of IP address

    9 replies

    rwpatterson
    New Member
    January 22, 2014
    Yes. Select ' FQDN' from the drop down box. (Fully Qualified Domain Name)
    Mahmood_Fraidoon
    New Member
    January 23, 2014
    I tried entering FQDN in different formats, still traffic is not going through that policy. I tried http://www.google.com www.google.com google.com
    robertwb2
    New Member
    January 30, 2014
    I am having the same problem. I would like to add a policy based on a certain address, however none of the traffic ever goes thru that Policy with the FQDN, I have moved it to the top of the policy list, I' ve tested it in many different ways, yet the traffic does not flow thru that policy like I have it set. I am also wondering what I am doing wrong. Thanks Robert
    Mahmood_Fraidoon
    New Member
    January 30, 2014
    Hello I found the root of my problem. My fortigate was pointing to my ISP DNS where my machine was pointing to domain controller DNS. Therefore both were resolving FQDN to different IPs. Change your fortigate or machine DNS and make them identical. that should solve your issue.
    Mahmood_Fraidoon
    New Member
    January 30, 2014
    FGT # diag test application dnsproxy ? 1. Clear dns cache 2. Show stats 3. Dump DNS setting 4. Reload FQDN 5. Requery FQDN 6. Dump FQDN compare it with you nslookup result from your machine.
    robertwb2
    New Member
    February 5, 2014
    Hi...thanks for the help! I checked my DNS settings on my Fortigate and they are the same as on my local machine, however, I' m still having trouble with the FQDN What I' m trying to do is Traffic Shape any traffic going to googlevideo.com - I' ve used the application sensors for YouTube, however, seems like we have lots of traffic every day to googlevideo that needs to be put into a lower priority, so I create a new policy and put in the destination as googlevideo.com (which I created as a FQDN in addresses) and put my traffic shaper on it, it still does not work....any hints and tips are much appreciated. THANK YOU Robert
    AtiT
    New Member
    February 7, 2014
    Hi, try to check the resolved FQDN addresses on Fortigate and client machines by nslookup whether they are the same: diagnose firewall fqdn list You can also try to clear the results with diagnose firewall fqdn flush - and wait what the new IP addresses will be found. They should be the same.
    robertwb2
    New Member
    February 7, 2014
    Ok! Great. Flushing out the cache did do the trick. My next quick question is how do I get it to see the traffic going to a subdomain of googlevideo.com? I know writing it like this: *.googlevideo.com isn' t working for me. Is there a way to even do that? To get all traffic going to " anything" .googlevideo.com to go thru that policy. Thanks so much for the help so far! Robert
    Nihas
    New Member
    May 13, 2015

    Hi ,

    I want to have the firewall synced with the DNS server.How can i forcefully try to get the IP's against DNS.

    I did a dia firewall fqdn flush and now I cannot see any DNS entries on ' dia firewall fqdn list".

     

    Please help

    Christopher_McMullan
    Staff
    Staff
    May 14, 2015

    Could you try editing and saving one of the objects again, then saving one of the policies the objects are bound to as destinations?