Description | This article describes the behavior of FQDN object in Firewall policy in Hyperscale Firewall |
Scope | FortiGate. |
Solution |
FQDN objects are not supported in the Hyperscale Firewall policy. However, only the VDOM with Hyperscale enabled is affected.
Enable the Hyperscale firewall features for FortiGate:
config global config system np set policy-offload-level full-offload end
FQDN object still can be used in the Firewall Policy:
Enable full-offload to specific VDOM:
config vdom edit test-hw config system setting set policy-offload-level full-offload end
FQDN objects are not selectable on the firewall policy. Other firewall address that are not selectable on Hyperscale Firewall include Device(MAC Address) and Dynamic. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.