Created on
03-21-2025
03:29 AM
Edited on
06-23-2025
12:34 AM
By
Jean-Philippe_P
| Description | This article describes best practices for configuring routing with FQDN destinations in a local breakout. |
| Scope | FortiGate v7.2.x, v7.4.x, v7.6.x. |
| Solution |
When setting up an explicit proxy for a local breakout, FQDN objects are commonly used as the destination for static routes. However, in this environment, there can be a slight time lag between the expiration of the FQDN cache TTL and the update of the route (RIB/FIB) after the DNS re-query resolves the IP address. This can temporarily cause communication failures. Therefore, the use of static routes is not recommended in this scenario.
Note: This does not apply to wildcard FQDN objects.
config system dns set fqdn-min-refresh 10 <----- <10> to <3600>. end
Refer to the following KB article for settings: Technical Tip: Improve FQDN re-query interval on FortiGate.
config firewall address
Refer to the following KB articles for settings: Technical Tip: Explanation of the FQDN default cache-ttl Technical Tip: Using a wildcard FQDN
Note: When the FQDN cache is updated, the routing table is also updated each time, requiring re-evaluation of related sessions. Considering the resources of FortiGate resources, a policy route is still recommended. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.