Created on 06-07-2021 12:40 PM Edited on 03-21-2024 11:27 PM By Jean-Philippe_P
Description
This article describes how to explain why the user defined FQDN Wildcards may not be working as expected.
It is possible that a scenario where an FQDN Wildcard object is created and although it is used in a firewall policy, the traffic is not being allowed.
This usually happens, if there is no UDP DNS session helper enabled, as the traffic will not be correctly matched because DNS resolution will not be performed properly.
This helper is enabled by default but it may have been removed for some reason, so always check before using FQDN Wildcards.
Solution
Consider the following session helper configuration:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.