Skip to main content
David_Tan
New Member
May 14, 2019
Question

Wildcard DNS A record

  • May 14, 2019
  • 12 replies
  • 20276 views

Hi,

 

I need to setup a wildcard domain to get an internal file hosting server running. How can i go about this? I am using the DNS server in Fortigate 101E. When i tried to put a * in the hostname field when creating an A record, the UI says it is an invalid domain.

 

Any help or guidance will be much appreciated. Thank you.

    12 replies

    sw2090
    SuperUser
    SuperUser
    May 15, 2019

    Yes "*" is indeed an invalid domain since that would mean every domain in the whole world :)

     

    I gues what you want is something like "any subdomain" of your domain.

    I'd try to set this as FQDN...however I up to now never needed this on a FGT DNS so cannot say for sure..

    ch2
    New Member
    May 29, 2019

    Hi,

     

    I have same problem, how add all subdomains in one record?

    emnoc
    New Member
    May 29, 2019

    1st no such thing exist from a DNS RR for "wildcard" domain in our FortiOS appliances

     

    2nd what specifically are you trying todo? And why do you think you need it ?

     

    I seen alot of mis-use for . "wildcard" A record an it will screw up search engines.

     

    just my 2cts

     

    Ken 

     

    Michael1030
    New Member
    November 25, 2021

    what is going here? Is there a solution? I also miss an option to insert a A record for the complete domain, not only the * option like for:

    example.com  192.168.100.1

    NimbleIT
    New Member
    June 27, 2022

    I used the @ symbol for the field "Hostname" and it seems to have worked.

    Markus_M
    Staff & Editor
    Staff & Editor
    June 27, 2022

    Hello Michael,

     

    what are you trying to accomplish?

    DNS does not support and is not intended to answer for a wildcard entry.

    That works with certificates, but a * is not a valid A-record entry in any DNS server I know of.

    I did some research and found this is indeed possible, although it will have expected adverse effects.

    I don't think you can make the FortiGate respond to any query of a domain with the same IP address. This makes only sense in a captive portal environment (internal), that however is limited as the FortiGate would have to respond not only to that one domain, but ALL domains with the same IP for internal users.

     

    Best regards,

     

    Markus

     

    TimUK
    New Member
    September 16, 2022

    Back to what another had previously commented on this ticket, re DNS specs. 

     

    Hm this is FortiOS specific behavior. Looks like Fortinet doesn't meet the DNS specs.

     

    basically in a DNS Zone it is definitely allowed to set a wildcard

     

    * IN A <ip>  does always mean *.domain.tld (i.e. anything not matched by other A entries in the zone).

     

    And no this does not mean any domain in the world as it is only valid in a zone. This means it is only valid for subdomains of 2nd level domain the zone is for.

     

    I have the same problem now, AD and F5 DNS can do *. A records, now I need to do the same to rewrite a subzone for our development team's isolated environment, and its a section that needs to use different DNS, so DNS-Server works great for this, all but for this one roadblock I've just hit. 

     

    Kind Regards, 

     

    Tim 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!