FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
lbruno
Staff
Staff
Article Id 198509

Description

 

This article describes how to explain why the user defined FQDN Wildcards may not be working as expected.

It is possible that a scenario where an FQDN Wildcard object is created and although it is used in a firewall policy, the traffic is not being allowed.

This usually happens, if there is no UDP DNS session helper enabled, as the traffic will not be correctly matched because DNS resolution will not be performed properly.

This helper is enabled by default but it may have been removed for some reason, so always check before using FQDN Wildcards.


Solution

 

Consider the following session helper configuration:



 
 
 
 
 
 
 
 
 

 
 
 
 
 
 
 
Note: If the DNS query from an endpoint is made to an internal DNS Servers and this DNS traffic does not pass through the FortiGate, then the query from the DNS Server to the Forwarder (could be internal or external),  to resolve the FQDN has to go through the FortiGate, so FortiGate can cache the resolution and update the wildcard FQDN object.
 
Related articles: