FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pciurea
Staff & Editor
Staff & Editor
Article Id 197781

Description

 

This article describes how to use a FQDN firewall address object in a static route.

 

Scope

 

FortiGate.


Solution

 

If dynamically updated FQDN addresses need to be referenced in a static route, here is how to achieve this:

First, create the Firewall object by going to Policy & Objects -> Addresses, select 'Create new' and choose Address, change the Type to FQDN, fill out the Name and FQDN parameters, and enable 'Static route configuration'.

 
Use the newly created Firewall address in a static route:
Go to Network -> Static Routes and select Create New, change the Destination by selecting 'Named Address', choose the FQDN address created in the previous step, fill out the outgoing Interface, and the Gateway Address.
 
 
Address groups can also be referenced in a static route, but all address members need to have the 'Static route configuration' enabled.
In case any of the members do not have this enabled, the 'Static route configuration' switch is grayed out.

 

Related article:

Technical Tip: How to create a static route on FortiGate from the GUI Interface